Re: [RFC PATCH v3 4/5] selinux: introduce kdbus names into the policy

2015-10-09 Thread Stephen Smalley
On 10/07/2015 07:08 PM, Paul Moore wrote: SELinux treats kdbus service names as objects and therefore needs a mechanism to map service names to security labels. This patch adds support for loading kdbus name/label matches with the security policy. The patch supports service name prefix matching

[RFC PATCH v3 4/5] selinux: introduce kdbus names into the policy

2015-10-07 Thread Paul Moore
SELinux treats kdbus service names as objects and therefore needs a mechanism to map service names to security labels. This patch adds support for loading kdbus name/label matches with the security policy. The patch supports service name prefix matching to lessen the burden on the policy develope