selinux: Report permissive mode in avc: denied messages.
authorStephen Smalley <sds@tycho.nsa.gov>
Tue, 29 Apr 2014 18:29:04 +0000 (11:29 -0700)
committerStephen Smalley <sds@tycho.nsa.gov>
Thu, 1 May 2014 17:19:04 +0000 (10:19 -0700)
commit6cb247b4ad17862ca47cb251c23b69a2dc321e89
tree37e42931fb6d9ca2bb66ed7c7c2824430559fd06
parent77232898045d67b125d33399c91ae141d3e3c6c1
selinux: Report permissive mode in avc: denied messages.

We cannot presently tell from an avc: denied message whether access was in
fact denied or was allowed due to global or per-domain permissive mode.
Add a permissive= field to the avc message to reflect this information.

Change-Id: I78176f8184e01226ece12f0eb38760cdcdc1ff87
Signed-off-by: Stephen Smalley <sds@tycho.nsa.gov>
security/selinux/avc.c
security/selinux/hooks.c
security/selinux/include/avc.h