summaryrefslogtreecommitdiff
path: root/tools/docs/parse-headers.py
diff options
context:
space:
mode:
authorJann Horn <jannh@google.com>2025-09-26 01:45:07 +0200
committerMimi Zohar <zohar@linux.ibm.com>2025-10-16 11:12:20 -0400
commit43369273518f57b7d56c1cf12d636a809b7bd81b (patch)
treed7a7e3d28552c1b1f6c2e8fd4467e38c93209e01 /tools/docs/parse-headers.py
parent345123d650db724d53ffee84d7365008c6f729de (diff)
ima: add fs_subtype condition for distinguishing FUSE instances
Linux systems often use FUSE for several different purposes, where the contents of some FUSE instances can be of more interest for auditing than others. Allow distinguishing between them based on the filesystem subtype (s_subtype) using the new condition "fs_subtype". The subtype string is supplied by userspace FUSE daemons when a FUSE connection is initialized, so policy authors who want to filter based on subtype need to ensure that FUSE mount operations are sufficiently audited or restricted. Signed-off-by: Jann Horn <jannh@google.com> Signed-off-by: Mimi Zohar <zohar@linux.ibm.com>
Diffstat (limited to 'tools/docs/parse-headers.py')
0 files changed, 0 insertions, 0 deletions