diff options
Diffstat (limited to 'Documentation/ABI/testing/ima_policy')
| -rw-r--r-- | Documentation/ABI/testing/ima_policy | 12 |
1 files changed, 6 insertions, 6 deletions
diff --git a/Documentation/ABI/testing/ima_policy b/Documentation/ABI/testing/ima_policy index 6434f0df012e..6cd6daefaaed 100644 --- a/Documentation/ABI/testing/ima_policy +++ b/Documentation/ABI/testing/ima_policy | |||
| @@ -20,7 +20,7 @@ Description: | |||
| 20 | lsm: [[subj_user=] [subj_role=] [subj_type=] | 20 | lsm: [[subj_user=] [subj_role=] [subj_type=] |
| 21 | [obj_user=] [obj_role=] [obj_type=]] | 21 | [obj_user=] [obj_role=] [obj_type=]] |
| 22 | 22 | ||
| 23 | base: func:= [BPRM_CHECK][FILE_MMAP][INODE_PERMISSION] | 23 | base: func:= [BPRM_CHECK][FILE_MMAP][FILE_CHECK] |
| 24 | mask:= [MAY_READ] [MAY_WRITE] [MAY_APPEND] [MAY_EXEC] | 24 | mask:= [MAY_READ] [MAY_WRITE] [MAY_APPEND] [MAY_EXEC] |
| 25 | fsmagic:= hex value | 25 | fsmagic:= hex value |
| 26 | uid:= decimal value | 26 | uid:= decimal value |
| @@ -40,11 +40,11 @@ Description: | |||
| 40 | 40 | ||
| 41 | measure func=BPRM_CHECK | 41 | measure func=BPRM_CHECK |
| 42 | measure func=FILE_MMAP mask=MAY_EXEC | 42 | measure func=FILE_MMAP mask=MAY_EXEC |
| 43 | measure func=INODE_PERM mask=MAY_READ uid=0 | 43 | measure func=FILE_CHECK mask=MAY_READ uid=0 |
| 44 | 44 | ||
| 45 | The default policy measures all executables in bprm_check, | 45 | The default policy measures all executables in bprm_check, |
| 46 | all files mmapped executable in file_mmap, and all files | 46 | all files mmapped executable in file_mmap, and all files |
| 47 | open for read by root in inode_permission. | 47 | open for read by root in do_filp_open. |
| 48 | 48 | ||
| 49 | Examples of LSM specific definitions: | 49 | Examples of LSM specific definitions: |
| 50 | 50 | ||
| @@ -54,8 +54,8 @@ Description: | |||
| 54 | 54 | ||
| 55 | dont_measure obj_type=var_log_t | 55 | dont_measure obj_type=var_log_t |
| 56 | dont_measure obj_type=auditd_log_t | 56 | dont_measure obj_type=auditd_log_t |
| 57 | measure subj_user=system_u func=INODE_PERM mask=MAY_READ | 57 | measure subj_user=system_u func=FILE_CHECK mask=MAY_READ |
| 58 | measure subj_role=system_r func=INODE_PERM mask=MAY_READ | 58 | measure subj_role=system_r func=FILE_CHECK mask=MAY_READ |
| 59 | 59 | ||
| 60 | Smack: | 60 | Smack: |
| 61 | measure subj_user=_ func=INODE_PERM mask=MAY_READ | 61 | measure subj_user=_ func=FILE_CHECK mask=MAY_READ |
