]> git.ipfire.org Git - thirdparty/systemd.git/commit - src/core/service.c
socket: introduce SELinuxContextFromNet option
authorMichal Sekletar <msekleta@redhat.com>
Thu, 24 Jul 2014 08:40:28 +0000 (10:40 +0200)
committerMichal Sekletar <msekleta@redhat.com>
Fri, 19 Sep 2014 10:32:06 +0000 (12:32 +0200)
commit16115b0a7b7cdf08fb38084d857d572d8a9088dc
tree2695c51cb8574ca2f1c6ea7bb90db11c4b5a88a2
parent863f3ce0d050f005839f6aa41fe7bac5478a7b5e
socket: introduce SELinuxContextFromNet option

This makes possible to spawn service instances triggered by socket with
MLS/MCS SELinux labels which are created based on information provided by
connected peer.

Implementation of label_get_child_mls_label derived from xinetd.

Reviewed-by: Paul Moore <pmoore@redhat.com>
man/systemd.socket.xml
src/core/execute.c
src/core/execute.h
src/core/load-fragment-gperf.gperf.m4
src/core/service.c
src/core/service.h
src/core/socket.c
src/core/socket.h
src/shared/label.c
src/shared/label.h