2
0
mirror of https://gitlab.com/apparmor/apparmor synced 2025-08-22 10:07:12 +00:00

Update Release_Notes_4.0 alpha2

John Johansen 2023-07-02 02:31:48 +00:00
parent e4ad2a6ad9
commit d10b68158f

@ -33,8 +33,16 @@ wip - not in this alpha, not guaranteed to land in 4.0
- replace unconfined
- mount, rename, hardlink restrictions, requires tracking
- bpf
- ioctl
- module
- ns tracking
- pivot root var
- deal with stacked attachment lookup
- optimize stacking name lookup to
- single buffer alloc
- single name lookup
- setns
-
- audit control flags audit.mode=XXX
- prompt, kill, unconfined
@ -45,6 +53,7 @@ wip - not in this alpha, not guaranteed to land in 4.0
- audit.mode flag control
- allow all
- aa_load
- drop root check
- sysv mqueue
- debug flags
- io_uring
@ -53,8 +62,18 @@ wip - not in this alpha, not guaranteed to land in 4.0
- improved rule prefixes
- allow all
- policy overlays
- dfa merge in kernel
-
- extended xindex
- user conditional
- policy
- attachment
- user mediation
- conditionals
- owner
- mac_override (for change_hat, hardlink, mv, bind mount)
- case insensite fs ???
-
- module mediation
- boolean ops
- raw text in policy