Hi James, One small patch to wrap the SELinux cgroup labeling support with a policy capability; this helps prevents breakage on Android and perhaps other userspaces as well. Everything passes the selinux-testsuite, please merge and pass along to Linus. Thanks, -Paul --- The following changes since commit 1ea0ce40690dff38935538e8dab7b12683ded0d3: selinux: allow changing labels for cgroupfs (2017-02-07 22:17:47 -0500) are available in the git repository at: git://git.infradead.org/users/pcmoore/selinux stable-4.11 for you to fetch changes up to 6b65b78139acf0b5984bcab8c2dfd001d45683c0: selinux: wrap cgroup seclabel support with its own policy capability (2017-02-28 16:41:44 -0500) ---------------------------------------------------------------- Stephen Smalley (1): selinux: wrap cgroup seclabel support with its own policy capability security/selinux/hooks.c | 7 ++++--- security/selinux/include/security.h | 2 ++ security/selinux/selinuxfs.c | 3 ++- security/selinux/ss/services.c | 4 ++++ 4 files changed, 12 insertions(+), 4 deletions(-) -- paul moore security @ redhat _______________________________________________ Selinux mailing list Selinux@xxxxxxxxxxxxx To unsubscribe, send email to Selinux-leave@xxxxxxxxxxxxx. To get help, send an email containing "help" to Selinux-request@xxxxxxxxxxxxx.