• Mimi Zohar's avatar
    ima: rename IMA_ACTION_FLAGS to IMA_NONACTION_FLAGS · aae6ccbd
    Mimi Zohar authored
    Simple policy rule options, such as fowner, uid, or euid, can be checked
    immediately, while other policy rule options, such as requiring a file
    signature, need to be deferred.
    
    The 'flags' field in the integrity_iint_cache struct contains the policy
    action', 'subaction', and non action/subaction.
    
    action: measure/measured, appraise/appraised, (collect)/collected,
            audit/audited
    subaction: appraise status for each hook (e.g. file, mmap, bprm, read,
            creds)
    non action/subaction: deferred policy rule options and state
    
    Rename the IMA_ACTION_FLAGS to IMA_NONACTION_FLAGS.
    Reviewed-by: default avatarStefan Berger <stefanb@linux.ibm.com>
    Signed-off-by: default avatarMimi Zohar <zohar@linux.ibm.com>
    aae6ccbd
integrity.h 7.39 KB