Re: [PATCH 2/2 v2] Smack: allow multiple labels in onlycap

2015-06-02 Thread Casey Schaufler
On 6/2/2015 2:23 AM, Rafal Krypa wrote: > Smack onlycap allows limiting of CAP_MAC_ADMIN and CAP_MAC_OVERRIDE to > processes running with the configured label. But having single privileged > label is not enough in some real use cases. On a complex system like Tizen, > there maybe few programs that

[PATCH 2/2 v2] Smack: allow multiple labels in onlycap

2015-06-02 Thread Rafal Krypa
Smack onlycap allows limiting of CAP_MAC_ADMIN and CAP_MAC_OVERRIDE to processes running with the configured label. But having single privileged label is not enough in some real use cases. On a complex system like Tizen, there maybe few programs that need to configure Smack policy in run-time and r