0ed3b28ab8
ipc: AppArmor ipc is currently limited to mediation done by file mediation and basic ptrace tests. Improved mediation is a wip. rlimits: AppArmor provides basic abilities to set and control rlimits at a per profile level. Only resources specified in a profile are controled or set. AppArmor rules set the hard limit to a value <= to the current hard limit (ie. they can not currently raise hard limits), and if necessary will lower the soft limit to the new hard limit value. AppArmor does not track resource limits to reset them when a profile is left so that children processes inherit the limits set by the parent even if they are not confined by the same profile. Capabilities: AppArmor provides a per profile mask of capabilities, that will further restrict. Signed-off-by: John Johansen <john.johansen@canonical.com> Signed-off-by: James Morris <jmorris@namei.org>
28 lines
732 B
C
28 lines
732 B
C
/*
|
|
* AppArmor security module
|
|
*
|
|
* This file contains AppArmor ipc mediation function definitions.
|
|
*
|
|
* Copyright (C) 1998-2008 Novell/SUSE
|
|
* Copyright 2009-2010 Canonical Ltd.
|
|
*
|
|
* This program is free software; you can redistribute it and/or
|
|
* modify it under the terms of the GNU General Public License as
|
|
* published by the Free Software Foundation, version 2 of the
|
|
* License.
|
|
*/
|
|
|
|
#ifndef __AA_IPC_H
|
|
#define __AA_IPC_H
|
|
|
|
#include <linux/sched.h>
|
|
|
|
struct aa_profile;
|
|
|
|
int aa_may_ptrace(struct task_struct *tracer_task, struct aa_profile *tracer,
|
|
struct aa_profile *tracee, unsigned int mode);
|
|
|
|
int aa_ptrace(struct task_struct *tracer, struct task_struct *tracee,
|
|
unsigned int mode);
|
|
|
|
#endif /* __AA_IPC_H */
|