Re: [dm-devel] [RFC PATCH v9 08/16] ipe: add permissive toggle

2023-03-02 Thread Paul Moore
On Mon, Jan 30, 2023 at 5:58 PM Fan Wu wrote: > > From: Deven Bowers > > IPE, like SELinux, supports a permissive mode. This mode allows policy > authors to test and evaluate IPE policy without it effecting their > programs. When the mode is changed, a 1404 AUDIT_MAC_STATUS > be reported. > > Thi

[dm-devel] [RFC PATCH v9 08/16] ipe: add permissive toggle

2023-01-30 Thread Fan Wu
From: Deven Bowers IPE, like SELinux, supports a permissive mode. This mode allows policy authors to test and evaluate IPE policy without it effecting their programs. When the mode is changed, a 1404 AUDIT_MAC_STATUS be reported. This patch adds the following audit records: audit: MAC_STATUS