mirror of
https://gitlab.com/apparmor/apparmor
synced 2025-08-30 22:05:27 +00:00
Update Kernel_Feature_Matrix
@@ -3,7 +3,7 @@
|
||||
|
||||
| Kernel Version | Feature | Required userspace version and notes |
|
||||
|----------------|---------|--------------------------------------|
|
||||
| 2.6.36 | Base functionality lands upstream mediation of<sup>1</sup>: <ul><li>File<ul><li>owner conditional</li><li>read, write, link, lock, mmap exec</li></ul></li><li>Execute<ul><li>[pP]x, [cC]x, ix, ux, [pP]ix, [pP]ux named transitions</li><li>attachment conditional separate from profile name</li></ul></li><li>Change hat<ul><li>single hat</li></ul></li><li>Change Profile</li><li>Capability</li><li>policy namespaces created through policy load</li><li>rlimit</li><li>Bug fixes and code cleanups</li></ul> | ```AppArmor 2.5.1``` |
|
||||
| 2.6.36 | Base functionality lands upstream mediation of<sup>1</sup>: <ul><li>File<ul><li>owner conditional</li><li>read, write, link, lock, mmap exec</li></ul></li><li>Execute<ul><li>[pP]x, [cC]x, ix, ux, [pP]ix, [pP]ux named transitions</li><li>attachment conditional separate from profile name</li></ul></li><li>Change hat<ul><li>single hat</li></ul></li><li>Change Profile</li><li>Capability</li><li>policy namespaces created through policy load</li><li>rlimit</li><li>Bug fixes and code cleanups</li></ul> | ```1``` AppArmor 2.5.1 |
|
||||
| 2.6.37 - 3.3| Bug fixes and code cleanups | |
|
||||
| 3.4 | <ul><li>Add support for extensible policydb</li><li>feature set<ul><li>add <i>features/</i> directory as a userspace api to discover kernel supported feature set</li><li>add file mediation details</li><li>add capability mediation details</li><li>export known rlimit mappings</li></ul></li></ul> | |
|
||||
| 3.5 | Fail exec transitions due to no_new_privs<ul><li>unconfined is allowed to transition to anything</li><li>inherit is allowed when task has nnp set</li><li>all other domain transitions are blocked when a task has nnp set</li><li>Bug fixes and code cleanups</li></ul> | |
|
||||
|
Reference in New Issue
Block a user