kernel_optimize_test/security
Eric Paris 6ccd045630 ima: handle multiple rules per write
Currently IMA will only accept one rule per write().  This patch allows IMA to
accept writes which contain multiple rules but only processes one rule per
write.  \n is used as the delimiter between rules.  IMA will return a short
write indicating that it only accepted up to the first \n.

This allows simple userspace utilities like cat to be used to load an IMA
policy instead of needing a special userspace utility that understood 'one
write per rule'

Signed-off-by: Eric Paris <eparis@redhat.com>
Acked-by: Mimi Zohar <zohar@us.ibm.com>
Signed-off-by: James Morris <jmorris@namei.org>
2010-04-21 09:58:13 +10:00
..
integrity/ima ima: handle multiple rules per write 2010-04-21 09:58:13 +10:00
keys security: remove dead hook key_session_to_parent 2010-04-12 12:19:18 +10:00
selinux SELinux: return error codes on policy load failure 2010-04-21 08:58:49 +10:00
smack SMACK: remove dead cred_commit hook 2010-04-08 09:20:21 +10:00
tomoyo Merge branch 'master' into next 2010-03-31 08:39:27 +11:00
capability.c security: remove dead hook acct 2010-04-12 12:19:19 +10:00
commoncap.c Security: Fix the comment of cap_file_mmap() 2010-04-20 08:47:11 +10:00
device_cgroup.c
inode.c get rid of pointless checks after simple_pin_fs() 2010-01-26 22:22:26 -05:00
Kconfig
lsm_audit.c
Makefile
min_addr.c
security.c security: remove dead hook acct 2010-04-12 12:19:19 +10:00