From mboxrd@z Thu Jan 1 00:00:00 1970 From: Michael Stone Subject: disablenetwork (v5) patches Date: Fri, 15 Jan 2010 03:10:28 -0500 Message-ID: <20100115081028.GA14004@heat> References: <20100114173639.GA15587@us.ibm.com> Mime-Version: 1.0 Content-Type: text/plain; charset=us-ascii; format=flowed Cc: netdev@vger.kernel.org, linux-security-module@vger.kernel.org, Andi Kleen , David Lang , Oliver Hartkopp , Alan Cox , Herbert Xu , Valdis Kletnieks , Bryan Donlan , Evgeniy Polyakov , "C. Scott Ananian" , James Morris , "Eric W. Biederman" , Bernie Innocenti , Mark Seaborn , Randy Dunlap , =?iso-8859-1?Q?Am=E9rico?= Wang , Tetsuo Handa , Samir Bellabes , Casey Schaufler , "Serge E. Hallyn" , Pavel Machek , Al Viro Content-Disposition: inline In-Reply-To: <20100114173639.GA15587@us.ibm.com> Sender: linux-security-module-owner@vger.kernel.org List-Id: netdev.vger.kernel.org As promised, here are patches implementing and documenting a CAP_SETPCAP-gated "enable" bit along with a couple of other tweaks discussed earlier in the thread. For ease of development and review, the following four patches extend the disablenetwork (v4) patch series rather than replacing it. Enjoy, Michael