Provide a method to enforce a deny on a specific capability for all applications regardless of their policies. This goes against the philosophy of WSM Default and should be used sparingly as a way to hot patch systems when an incident occurs. It should be advertised this way and understood this way by WSM Default.
Reserved keyword: Exec=!
Considerations:
- WSM Default must log all decisions made on an emergency policy override and complain loudly
- This must be advertised as only for emergency response!
- Requires hooking the override policy in get_permission to allow dual sources of policy
- Also means this backend could be plugged on top of another one
- Only [Soft] Deny is applicable. When a rule isn't present in the override source of policy, the normal policy file of an app:UID couple should be used
Methods: TBC
Provide a method to enforce a deny on a specific capability for all applications regardless of their policies. This goes against the philosophy of WSM Default and should be used sparingly as a way to hot patch systems when an incident occurs. It should be advertised this way and understood this way by WSM Default.
Reserved keyword: Exec=!
Considerations:
Methods: TBC