Searched hist:"0 ed3b28ab8bf460a3a026f3f1782bf4c53840184" (Results 1 – 6 of 6) sorted by relevance
/openbmc/linux/security/apparmor/include/ |
H A D | resource.h | 0ed3b28ab8bf460a3a026f3f1782bf4c53840184 Thu Jul 29 16:48:05 CDT 2010 John Johansen <john.johansen@canonical.com> AppArmor: mediation of non file objects
ipc: AppArmor ipc is currently limited to mediation done by file mediation and basic ptrace tests. Improved mediation is a wip.
rlimits: AppArmor provides basic abilities to set and control rlimits at a per profile level. Only resources specified in a profile are controled or set. AppArmor rules set the hard limit to a value <= to the current hard limit (ie. they can not currently raise hard limits), and if necessary will lower the soft limit to the new hard limit value.
AppArmor does not track resource limits to reset them when a profile is left so that children processes inherit the limits set by the parent even if they are not confined by the same profile.
Capabilities: AppArmor provides a per profile mask of capabilities, that will further restrict.
Signed-off-by: John Johansen <john.johansen@canonical.com> Signed-off-by: James Morris <jmorris@namei.org>
|
H A D | capability.h | 0ed3b28ab8bf460a3a026f3f1782bf4c53840184 Thu Jul 29 16:48:05 CDT 2010 John Johansen <john.johansen@canonical.com> AppArmor: mediation of non file objects
ipc: AppArmor ipc is currently limited to mediation done by file mediation and basic ptrace tests. Improved mediation is a wip.
rlimits: AppArmor provides basic abilities to set and control rlimits at a per profile level. Only resources specified in a profile are controled or set. AppArmor rules set the hard limit to a value <= to the current hard limit (ie. they can not currently raise hard limits), and if necessary will lower the soft limit to the new hard limit value.
AppArmor does not track resource limits to reset them when a profile is left so that children processes inherit the limits set by the parent even if they are not confined by the same profile.
Capabilities: AppArmor provides a per profile mask of capabilities, that will further restrict.
Signed-off-by: John Johansen <john.johansen@canonical.com> Signed-off-by: James Morris <jmorris@namei.org>
|
H A D | ipc.h | 0ed3b28ab8bf460a3a026f3f1782bf4c53840184 Thu Jul 29 16:48:05 CDT 2010 John Johansen <john.johansen@canonical.com> AppArmor: mediation of non file objects
ipc: AppArmor ipc is currently limited to mediation done by file mediation and basic ptrace tests. Improved mediation is a wip.
rlimits: AppArmor provides basic abilities to set and control rlimits at a per profile level. Only resources specified in a profile are controled or set. AppArmor rules set the hard limit to a value <= to the current hard limit (ie. they can not currently raise hard limits), and if necessary will lower the soft limit to the new hard limit value.
AppArmor does not track resource limits to reset them when a profile is left so that children processes inherit the limits set by the parent even if they are not confined by the same profile.
Capabilities: AppArmor provides a per profile mask of capabilities, that will further restrict.
Signed-off-by: John Johansen <john.johansen@canonical.com> Signed-off-by: James Morris <jmorris@namei.org>
|
/openbmc/linux/security/apparmor/ |
H A D | capability.c | 0ed3b28ab8bf460a3a026f3f1782bf4c53840184 Thu Jul 29 16:48:05 CDT 2010 John Johansen <john.johansen@canonical.com> AppArmor: mediation of non file objects
ipc: AppArmor ipc is currently limited to mediation done by file mediation and basic ptrace tests. Improved mediation is a wip.
rlimits: AppArmor provides basic abilities to set and control rlimits at a per profile level. Only resources specified in a profile are controled or set. AppArmor rules set the hard limit to a value <= to the current hard limit (ie. they can not currently raise hard limits), and if necessary will lower the soft limit to the new hard limit value.
AppArmor does not track resource limits to reset them when a profile is left so that children processes inherit the limits set by the parent even if they are not confined by the same profile.
Capabilities: AppArmor provides a per profile mask of capabilities, that will further restrict.
Signed-off-by: John Johansen <john.johansen@canonical.com> Signed-off-by: James Morris <jmorris@namei.org>
|
H A D | resource.c | 0ed3b28ab8bf460a3a026f3f1782bf4c53840184 Thu Jul 29 16:48:05 CDT 2010 John Johansen <john.johansen@canonical.com> AppArmor: mediation of non file objects
ipc: AppArmor ipc is currently limited to mediation done by file mediation and basic ptrace tests. Improved mediation is a wip.
rlimits: AppArmor provides basic abilities to set and control rlimits at a per profile level. Only resources specified in a profile are controled or set. AppArmor rules set the hard limit to a value <= to the current hard limit (ie. they can not currently raise hard limits), and if necessary will lower the soft limit to the new hard limit value.
AppArmor does not track resource limits to reset them when a profile is left so that children processes inherit the limits set by the parent even if they are not confined by the same profile.
Capabilities: AppArmor provides a per profile mask of capabilities, that will further restrict.
Signed-off-by: John Johansen <john.johansen@canonical.com> Signed-off-by: James Morris <jmorris@namei.org>
|
H A D | ipc.c | 0ed3b28ab8bf460a3a026f3f1782bf4c53840184 Thu Jul 29 16:48:05 CDT 2010 John Johansen <john.johansen@canonical.com> AppArmor: mediation of non file objects
ipc: AppArmor ipc is currently limited to mediation done by file mediation and basic ptrace tests. Improved mediation is a wip.
rlimits: AppArmor provides basic abilities to set and control rlimits at a per profile level. Only resources specified in a profile are controled or set. AppArmor rules set the hard limit to a value <= to the current hard limit (ie. they can not currently raise hard limits), and if necessary will lower the soft limit to the new hard limit value.
AppArmor does not track resource limits to reset them when a profile is left so that children processes inherit the limits set by the parent even if they are not confined by the same profile.
Capabilities: AppArmor provides a per profile mask of capabilities, that will further restrict.
Signed-off-by: John Johansen <john.johansen@canonical.com> Signed-off-by: James Morris <jmorris@namei.org>
|