mirror of
https://github.com/torvalds/linux.git
synced 2026-10-07 05:31:08 -04:00
AppArmor policy needs to be able to be resolved based on the policy namespace a task is confined by. Add a base apparmorfs filesystem that (like nsfs) will exist as a kern mount and be accessed via jump_link through a securityfs file. Setup the base apparmorfs fns and data, but don't use it yet. Signed-off-by: John Johansen <[email protected]> Reviewed-by: Seth Arnold <[email protected]> Reviewed-by: Kees Cook <[email protected]>