forked from torvalds/linux
-
Notifications
You must be signed in to change notification settings - Fork 0
Commit
This commit does not belong to any branch on this repository, and may belong to a fork outside of the repository.
Adjusts for ReST markup and moves under LSM admin guide. Acked-by: John Johansen <[email protected]> Signed-off-by: Kees Cook <[email protected]> Signed-off-by: Jonathan Corbet <[email protected]>
- Loading branch information
Showing
6 changed files
with
28 additions
and
16 deletions.
There are no files selected for viewing
36 changes: 24 additions & 12 deletions
36
Documentation/security/apparmor.txt → Documentation/admin-guide/LSM/apparmor.rst
This file contains bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Original file line number | Diff line number | Diff line change |
---|---|---|
@@ -1,39 +1,51 @@ | ||
--- What is AppArmor? --- | ||
======== | ||
AppArmor | ||
======== | ||
|
||
What is AppArmor? | ||
================= | ||
|
||
AppArmor is MAC style security extension for the Linux kernel. It implements | ||
a task centered policy, with task "profiles" being created and loaded | ||
from user space. Tasks on the system that do not have a profile defined for | ||
them run in an unconfined state which is equivalent to standard Linux DAC | ||
permissions. | ||
|
||
--- How to enable/disable --- | ||
How to enable/disable | ||
===================== | ||
|
||
set ``CONFIG_SECURITY_APPARMOR=y`` | ||
|
||
set CONFIG_SECURITY_APPARMOR=y | ||
If AppArmor should be selected as the default security module then set:: | ||
|
||
If AppArmor should be selected as the default security module then | ||
set CONFIG_DEFAULT_SECURITY="apparmor" | ||
and CONFIG_SECURITY_APPARMOR_BOOTPARAM_VALUE=1 | ||
CONFIG_DEFAULT_SECURITY="apparmor" | ||
CONFIG_SECURITY_APPARMOR_BOOTPARAM_VALUE=1 | ||
|
||
Build the kernel | ||
|
||
If AppArmor is not the default security module it can be enabled by passing | ||
security=apparmor on the kernel's command line. | ||
``security=apparmor`` on the kernel's command line. | ||
|
||
If AppArmor is the default security module it can be disabled by passing | ||
apparmor=0, security=XXXX (where XXX is valid security module), on the | ||
kernel's command line | ||
``apparmor=0, security=XXXX`` (where ``XXXX`` is valid security module), on the | ||
kernel's command line. | ||
|
||
For AppArmor to enforce any restrictions beyond standard Linux DAC permissions | ||
policy must be loaded into the kernel from user space (see the Documentation | ||
and tools links). | ||
|
||
--- Documentation --- | ||
Documentation | ||
============= | ||
|
||
Documentation can be found on the wiki. | ||
Documentation can be found on the wiki, linked below. | ||
|
||
--- Links --- | ||
Links | ||
===== | ||
|
||
Mailing List - [email protected] | ||
|
||
Wiki - http://apparmor.wiki.kernel.org/ | ||
|
||
User space tools - https://launchpad.net/apparmor | ||
|
||
Kernel module - git://git.kernel.org/pub/scm/linux/kernel/git/jj/apparmor-dev.git |
This file contains bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Original file line number | Diff line number | Diff line change |
---|---|---|
|
@@ -33,4 +33,5 @@ the one "major" module (e.g. SELinux) if there is one configured. | |
.. toctree:: | ||
:maxdepth: 1 | ||
|
||
apparmor | ||
SELinux |
This file contains bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
This file contains bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Original file line number | Diff line number | Diff line change |
---|---|---|
|
@@ -11560,6 +11560,7 @@ W: apparmor.wiki.kernel.org | |
T: git git://git.kernel.org/pub/scm/linux/kernel/git/jj/apparmor-dev.git | ||
S: Supported | ||
F: security/apparmor/ | ||
F: Documentation/admin-guide/LSM/apparmor.rst | ||
|
||
LOADPIN SECURITY MODULE | ||
M: Kees Cook <[email protected]> | ||
|
This file contains bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
This file contains bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters