Introduce support for Mandatory Access Control and extensible

kernel access control.

Label IP fragment reassembly queues, permitting security features to
be maintained on those objects.  ipq_label will be used to manage
the reassembly of fragments into IP datagrams using security
properties.  This permits policies to deny the reassembly of fragments,
as well as influence the resulting label of a datagram following
reassembly.

Obtained from:	TrustedBSD Project
Sponsored by:	DARPA, NAI Labs
This commit is contained in:
Robert Watson 2002-07-30 23:09:20 +00:00
parent 19930ae546
commit 549e4c9e4e

View File

@ -68,6 +68,7 @@ struct ipq {
u_int32_t ipq_div_info; /* ipfw divert port & flags */
u_int16_t ipq_div_cookie; /* ipfw divert cookie */
#endif
struct label ipq_label; /* MAC label */
};
#endif /* _KERNEL */