apparmor: Allow filtering based on secmark policy
authorMatthew Garrett <mjg59@google.com>
Thu, 24 May 2018 20:27:47 +0000 (13:27 -0700)
committerJohn Johansen <john.johansen@canonical.com>
Wed, 3 Oct 2018 13:18:55 +0000 (06:18 -0700)
commitab9f2115081ab7ba63b77a759e0f3eb5d6463d7f
tree297c733145b44d2fd5119c385cb91eb0a6a54a33
parent9caafbe2b4cf4c635826a2832e93cf648605de8b
apparmor: Allow filtering based on secmark policy

Add support for dropping or accepting packets based on their secmark
tags.

Signed-off-by: Matthew Garrett <mjg59@google.com>
Signed-off-by: John Johansen <john.johansen@canonical.com>
security/apparmor/lsm.c
security/apparmor/net.c