ANDROID: selinux: modify RTM_GETNEIGH{TBL}
Map the permission gating RTM_GETNEIGH/RTM_GETNEIGHTBL messages to a new permission so that it can be distinguished from the other netlink route permissions in selinux policy. The new permission is triggered by a flag set in system images T and up. While the kernel supports the new nlmsg extended permission, the policy does not yet contain the new rules. Keep the support for the Android-specific policy until the new policy lands. Bug: 392913234 Bug: 353255679 Test: atest CtsSelinuxTargetSdk25TestCases Test: atest CtsSelinuxTargetSdk27TestCases Test: atest CtsSelinuxTargetSdk28TestCases Test: atest CtsSelinuxTargetSdk29TestCases Test: atest CtsSelinuxTargetSdk30TestCases Test: atest CtsSelinuxTargetSdkCurrentTestCases Signed-off-by:Bram Bonné <brambonne@google.com> Signed-off-by:
Thiébaud Weksteen <tweek@google.com> Change-Id: I8b34841d7afc97ec1db5dc01444fa26eb68a6e4b
Showing
- security/selinux/include/classmap.h 2 additions, 1 deletionsecurity/selinux/include/classmap.h
- security/selinux/include/security.h 6 additions, 0 deletionssecurity/selinux/include/security.h
- security/selinux/nlmsgtab.c 7 additions, 0 deletionssecurity/selinux/nlmsgtab.c
- security/selinux/ss/policydb.c 4 additions, 0 deletionssecurity/selinux/ss/policydb.c
- security/selinux/ss/policydb.h 2 additions, 0 deletionssecurity/selinux/ss/policydb.h
- security/selinux/ss/services.c 2 additions, 0 deletionssecurity/selinux/ss/services.c
Loading
Please register or sign in to comment