2
0
mirror of https://gitlab.com/apparmor/apparmor synced 2025-08-30 22:05:27 +00:00

Update Kernel_Feature_Matrix

John Johansen
2019-04-16 15:50:57 +00:00
parent 7e6ed6c8d2
commit 6dfb4df791

@@ -3,7 +3,7 @@
| Kernel Version | Feature | Required userspace version and notes |
|----------------|---------|--------------------------------------|
| 2.6.36 | Base functionality lands upstream mediation of<sup>1</sup>: <ul><li>File<ul><li>owner conditional</li><li>read, write, link, lock, mmap exec</li></ul></li><li>Execute<ul><li>[pP]x, [cC]x, ix, ux, [pP]ix, [pP]ux named transitions</li><li>attachment conditional separate from profile name</li></ul></li><li>Change hat<ul><li>single hat</li></ul></li><li>Change Profile</li><li>Capability</li><li>policy namespaces created through policy load</li><li>rlimit</li><li>Bug fixes and code cleanups</li></ul> | ```AppArmor 2.5.1``` |
| 2.6.36 | Base functionality lands upstream mediation of<sup>1</sup>: <ul><li>File<ul><li>owner conditional</li><li>read, write, link, lock, mmap exec</li></ul></li><li>Execute<ul><li>[pP]x, [cC]x, ix, ux, [pP]ix, [pP]ux named transitions</li><li>attachment conditional separate from profile name</li></ul></li><li>Change hat<ul><li>single hat</li></ul></li><li>Change Profile</li><li>Capability</li><li>policy namespaces created through policy load</li><li>rlimit</li><li>Bug fixes and code cleanups</li></ul> | ```1``` AppArmor 2.5.1 |
| 2.6.37 - 3.3| Bug fixes and code cleanups | |
| 3.4 | <ul><li>Add support for extensible policydb</li><li>feature set<ul><li>add <i>features/</i> directory as a userspace api to discover kernel supported feature set</li><li>add file mediation details</li><li>add capability mediation details</li><li>export known rlimit mappings</li></ul></li></ul> | |
| 3.5 | Fail exec transitions due to no_new_privs<ul><li>unconfined is allowed to transition to anything</li><li>inherit is allowed when task has nnp set</li><li>all other domain transitions are blocked when a task has nnp set</li><li>Bug fixes and code cleanups</li></ul> | |