]> asedeno.scripts.mit.edu Git - linux.git/commit
selinux: enable genfscon labeling for tracefs
authorJeff Vander Stoep <jeffv@google.com>
Tue, 20 Jun 2017 16:35:33 +0000 (09:35 -0700)
committerPaul Moore <paul@paul-moore.com>
Tue, 20 Jun 2017 19:53:34 +0000 (15:53 -0400)
commit6a3911837da0a90ed599fd0a9836472f5e7ddf1b
tree603ab97d952ed13beb9beb40fcc7163f3a6a3337
parent0b4d3452b8b4a5309b4445b900e3cec022cca95a
selinux: enable genfscon labeling for tracefs

In kernel version 4.1, tracefs was separated from debugfs into its
own filesystem. Prior to this split, files in
/sys/kernel/debug/tracing could be labeled during filesystem
creation using genfscon or later from userspace using setxattr. This
change re-enables support for genfscon labeling.

Signed-off-by: Jeff Vander Stoep <jeffv@google.com>
Acked-by: Stephen Smalley <sds@tycho.nsa.gov>
Signed-off-by: Paul Moore <paul@paul-moore.com>
security/selinux/hooks.c