| commit | e1eddc1bde17e6c643e103949ac63e553b80ee84 | [log] [tgz] |
|---|---|---|
| author | David Howells <dhowells@redhat.com> | Thu Aug 29 17:01:34 2019 +0100 |
| committer | David Howells <dhowells@redhat.com> | Fri Oct 11 09:14:23 2019 +0100 |
| tree | 4684345c8ab5f54755de5be21dc27884a84a720f | |
| parent | 0b9c31597d817367bd30d214ff49d0614ea88e20 [diff] |
selinux: Implement the watch_key security hook Implement the watch_key security hook to make sure that a key grants the caller View permission in order to set a watch on a key. For the moment, the watch_devices security hook is left unimplemented as it's not obvious what the object should be since the queue is global and didn't previously exist. Signed-off-by: David Howells <dhowells@redhat.com> Acked-by: Stephen Smalley <sds@tycho.nsa.gov>