HomeFreeBSD

Introduce support for Mandatory Access Control and extensible

Description

Introduce support for Mandatory Access Control and extensible
kernel access control.

Label BPF descriptor objects, permitting security features to be
maintained on those objects. bd_label will be used to authorize
data flow from network interfaces to user processes. BPF
labels are protected using the same synchronization model as other
mutable data in the BPF descriptor.

Obtained from: TrustedBSD Project
Sponsored by: DARPA, NAI Labs

Details

Provenance
rwatsonAuthored on Jul 30 2002, 11:03 PM
Parents
rG55fb7830520c: Introduce support for Mandatory Access Control and extensible
Branches
Unknown
Tags
Unknown

Event Timeline