freebsd-skq/sys/security
Robert Watson 2b03c68008 Expand scope of the Biba policy to include some of the new entry
points available for enforcement:

  mac_biba_check_sysarch_ioperm() - Require Biba privilege to make
  use of privileged machine-dependent interfaces, protecting against
  bypass of the policy via various mechanisms.

  mac_biba_check_system_swapoff() - Require Biba privilege to disable
  swapping against a vnode target.

Obtained from:	TrustedBSD Project
Sponsored by:	DARPA, Network Associates Laboratories
2003-03-25 01:10:54 +00:00
..
mac Garbage collect FREEBSD_MAC_EXTATTR_NAME and FREEBSD_MAC_EXTATTR_NAMESPACE, 2003-03-23 02:09:20 +00:00
mac_biba Expand scope of the Biba policy to include some of the new entry 2003-03-25 01:10:54 +00:00
mac_bsdextended Back out M_* changes, per decision of the TRB. 2003-02-19 05:47:46 +00:00
mac_ifoff License and wording updates: NAI has authorized the removal of clause 2002-11-04 01:53:12 +00:00
mac_lomac Back out M_* changes, per decision of the TRB. 2003-02-19 05:47:46 +00:00
mac_mls Back out M_* changes, per decision of the TRB. 2003-02-19 05:47:46 +00:00
mac_none Default policies to on: if you load them or compile them into your 2002-12-10 16:20:34 +00:00
mac_partition Update MAC modules for changes in arguments for exec MAC policy 2002-11-08 18:04:36 +00:00
mac_portacl Including <sys/stdint.h> is (almost?) universally only to be able to use 2003-03-18 08:45:25 +00:00
mac_seeotheruids Default policies to on: if you load them or compile them into your 2002-12-10 16:20:34 +00:00
mac_stub Default policies to on: if you load them or compile them into your 2002-12-10 16:20:34 +00:00
mac_test Default policies to on: if you load them or compile them into your 2002-12-10 16:20:34 +00:00