xsm: add resource operation related xsm policy
authorDongxiao Xu <dongxiao.xu@intel.com>
Mon, 6 Oct 2014 10:29:16 +0000 (12:29 +0200)
committerJan Beulich <jbeulich@suse.com>
Mon, 6 Oct 2014 10:29:16 +0000 (12:29 +0200)
commit2a5e086e0bd6729b4a25536b9f978dedf3be52de
treef52ee9ea613aa2fd64efab18a6f47d9dc4ae81d7
parent443035c40ab6a0566133a55090532740c52d61d3
xsm: add resource operation related xsm policy

Add xsm policies for resource access related hypercall, such as MSR
access, port I/O read/write, and other related resource operations.

Signed-off-by: Dongxiao Xu <dongxiao.xu@intel.com>
Signed-off-by: Chao Peng <chao.p.peng@linux.intel.com>
Acked-by: Daniel De Graaf <dgdegra@tycho.nsa.gov>
Release-Acked-by: Konrad Rzeszutek Wilk <konrad.wilk@oracle.com>
tools/flask/policy/policy/modules/xen/xen.te
xen/xsm/flask/hooks.c
xen/xsm/flask/policy/access_vectors
xen/xsm/flask/policy/security_classes