Commit message (Collapse) | Author | Age | |
---|---|---|---|
* | SELinux: Add warning messages on network denial due to error | Paul Moore | 2008-01-29 |
| | | | | | | | | | | Currently network traffic can be sliently dropped due to non-avc errors which can lead to much confusion when trying to debug the problem. This patch adds warning messages so that when these events occur there is a user visible notification. Signed-off-by: Paul Moore <paul.moore@hp.com> Signed-off-by: James Morris <jmorris@namei.org> | ||
* | SELinux: Add a network node caching mechanism similar to the sel_netif_*() ↵ | Paul Moore | 2008-01-29 |
functions This patch adds a SELinux IP address/node SID caching mechanism similar to the sel_netif_*() functions. The node SID queries in the SELinux hooks files are also modified to take advantage of this new functionality. In addition, remove the address length information from the sk_buff parsing routines as it is redundant since we already have the address family. Signed-off-by: Paul Moore <paul.moore@hp.com> Signed-off-by: James Morris <jmorris@namei.org> |