Commit b62ee524 authored by Karol Lewandowski's avatar Karol Lewandowski Committed by Zbigniew Jędrzejewski-Szmek
Browse files

condition, man: Add support for ConditionSecurity=smack

According to Documentation/security/Smack.txt:
  In keeping with the intent of Smack, configuration data is minimal
  and not strictly required. The most important configuration step is
  mounting the smackfs pseudo filesystem.
This means that checking the mount point should be enough.
parent 539e0a4d
......@@ -984,8 +984,9 @@
may be used to check whether the given
security module is enabled on the
system. Currently the only recognized
values are <varname>selinux</varname>
and <varname>apparmor</varname>.
values are <varname>selinux</varname>,
<varname>apparmor</varname>, and
The test may be negated by prepending
an exclamation
......@@ -164,6 +164,8 @@ static bool test_security(const char *parameter) {
if (streq(parameter, "apparmor"))
return access("/sys/kernel/security/apparmor/", F_OK) == 0;
if (streq(parameter, "smack"))
return access("/sys/fs/smackfs", F_OK) == 0;
return false;
Markdown is supported
0% or .
You are about to add 0 people to the discussion. Proceed with caution.
Finish editing this message first!
Please register or to comment