selinux: allow per-file labeling for cgroupfs
authorAntonio Murdaca <runcom@redhat.com>
Thu, 9 Feb 2017 16:02:42 +0000 (17:02 +0100)
committerPaul Moore <paul@paul-moore.com>
Tue, 22 Aug 2017 19:38:18 +0000 (15:38 -0400)
commit901ef845fa2469c211ce3b1e955d9e7245ab5d50
treeb09c7e1bb1705c4db7dd5468b19fb7f243aa37b6
parent5d72801538eb59cfd9ca25d00aa439cfbc02ac9a
selinux: allow per-file labeling for cgroupfs

This patch allows genfscon per-file labeling for cgroupfs. For instance,
this allows to label the "release_agent" file within each
cgroup mount and limit writes to it.

Signed-off-by: Antonio Murdaca <amurdaca@redhat.com>
[PM: subject line and merge tweaks]
Signed-off-by: Paul Moore <paul@paul-moore.com>
security/selinux/hooks.c