Commit
This commit does not belong to any branch on this repository, and may belong to a fork outside of the repository.
Allow the sysadm user use the secretmem API
This is a follow-up commit to 41c4218 ("Add support for secretmem anon inode") which allowed the necessary permission to unconfined domain types. This commit allows it also for the sysadm_t domain. Note: Pages allocated with this method can never be swapped out of the physical memory and the system hibernation is blocked as long as any file descriptor created with this method exists, so this permission should be allowed to a very limited set of domains only. Resolves: rhbz#2270895
- Loading branch information