mirror of
https://github.com/torvalds/linux.git
synced 2026-04-18 23:03:57 -04:00
Add support for wildcard matching of network interface names. This is useful for auto-generated interfaces, for example podman creates network interfaces for containers with the naming scheme podman0, podman1, podman2, ... To maintain backward compatibility guard this feature with a new policy capability 'netif_wildcard'. Netifcon definitions are compared against in the order given by the policy, so userspace tools should sort them in a reasonable order. Signed-off-by: Christian Göttsche <cgzones@googlemail.com> Signed-off-by: Paul Moore <paul@paul-moore.com>
26 lines
579 B
C
26 lines
579 B
C
/* SPDX-License-Identifier: GPL-2.0 */
|
|
|
|
#ifndef _SELINUX_POLICYCAP_NAMES_H_
|
|
#define _SELINUX_POLICYCAP_NAMES_H_
|
|
|
|
#include "policycap.h"
|
|
|
|
/* clang-format off */
|
|
/* Policy capability names */
|
|
const char *const selinux_policycap_names[__POLICYDB_CAP_MAX] = {
|
|
"network_peer_controls",
|
|
"open_perms",
|
|
"extended_socket_class",
|
|
"always_check_network",
|
|
"cgroup_seclabel",
|
|
"nnp_nosuid_transition",
|
|
"genfs_seclabel_symlinks",
|
|
"ioctl_skip_cloexec",
|
|
"userspace_initial_context",
|
|
"netlink_xperm",
|
|
"netif_wildcard",
|
|
};
|
|
/* clang-format on */
|
|
|
|
#endif /* _SELINUX_POLICYCAP_NAMES_H_ */
|