HomeFreeBSD

Introduce support for Mandatory Access Control and extensible kernel

Description

Introduce support for Mandatory Access Control and extensible kernel
access control.

Label socket IPC objects, permitting security features to be maintained
at the granularity of the socket. Two labels are stored for each
socket: the label of the socket itself, and a cached peer label
permitting interogation of the remote endpoint. Since socket locking
is not yet present in the base tree, these objects are not locked,
but are assumed to follow the same semantics as other modifiable
entries in the socket structure.

Obtained from: TrustedBSD Project
Sponsored by: DARPA, NAI Labs

Details

Provenance
rwatsonAuthored on Jul 30 2002, 10:39 PM
Parents
rG87acada933d7: Introduce support for Mandatory Access Control and extensible
Branches
Unknown
Tags
Unknown

Event Timeline