linux/security/smack
Roman Kubiak 41a2d57516 Kernel threads excluded from smack checks
Adds an ignore case for kernel tasks,
so that they can access all resources.

Since kernel worker threads are spawned with
floor label, they are severely restricted by
Smack policy. It is not an issue without onlycap,
as these processes also run with root,
so CAP_MAC_OVERRIDE kicks in. But with onlycap
turned on, there is no way to change the label
for these processes.

Signed-off-by: Roman Kubiak <r.kubiak@samsung.com>
Acked-by: Casey Schaufler <casey@schaufler-ca.com>
2015-08-10 15:15:50 -07:00
..
Kconfig Smack: secmark support for netfilter 2015-01-20 16:34:25 -08:00
Makefile Smack: Repair netfilter dependency 2015-01-23 10:08:19 -08:00
smack_access.c Kernel threads excluded from smack checks 2015-08-10 15:15:50 -07:00
smack_lsm.c Smack: Three symbols that should be static 2015-07-31 12:12:17 -07:00
smack_netfilter.c netfilter: Make nf_hookfn use nf_hook_state. 2015-04-04 12:31:38 -04:00
smack.h Smack: IPv6 host labeling 2015-07-28 06:35:21 -07:00
smackfs.c Smack: Three symbols that should be static 2015-07-31 12:12:17 -07:00