[apparmor] [RFC] Support network policy for secmark labels

Matthew Garrett mjg59 at google.com
Fri May 18 19:06:15 UTC 2018


Secmark allows us to label packets with fairly arbitrary iptables rules,
and these patches give a mechanism for then applying Apparmor policy to
those labels. I haven't really thought through how this applies to
existing network policy, so feedback on that welcome.





More information about the AppArmor mailing list