| commit | 90935cf0264a814d1ca90ad92efe64002d3c6522 | [log] [tgz] |
|---|---|---|
| author | David Howells <dhowells@redhat.com> | Tue Oct 15 16:01:35 2019 +0100 |
| committer | David Howells <dhowells@redhat.com> | Tue Oct 15 22:12:05 2019 +0100 |
| tree | 49c4ddb30d7d09367a66c52a19ba1e9131ac07cf | |
| parent | fe4f3751d46da00d9c1a7f667e066f447fa1f9ea [diff] |
selinux: Implement the watch_key security hook Implement the watch_key security hook to make sure that a key grants the caller View permission in order to set a watch on a key. For the moment, the watch_devices security hook is left unimplemented as it's not obvious what the object should be since the queue is global and didn't previously exist. Signed-off-by: David Howells <dhowells@redhat.com> Acked-by: Stephen Smalley <sds@tycho.nsa.gov>