Cc: Andreas Gruenbacher <agruen@...>, Stephen Smalley <sds@...>, Pavel Machek <pavel@...>, <jjohansen@...>, <linux-kernel@...>, <linux-security-module@...>, <linux-fsdevel@...>
On Sun, Jun 10, 2007 at 10:09:18AM -0700, Crispin Cowan wrote:
A daemon using inotify can "instantly"[1] detect this and label the file
properly if it shows up.
Same daemon can do the re-label.
Same daemon can do this. And yes, it might take a ammount of time, but
the times that this happens in "real-life" on a "production" server is
quite small, if at all.
Again, same daemon can handle this logic.
SELinux already provides support for the whole mounted filesystem,
which, in real-life testing, seems to be quite sufficient. Also, the
SELinux developers are working on some changes to make this a bit more
fine-grained.
See also Stephan's previous comments about NFSv3 client directories and
multiple views having the potential to cause a lot of havoc.
I don't think that is necessary at all, see above for why.
No, do the labeling in userspace with a daemon using inotify to handle
the changing of the files around.
Or has this whole idea of a daemon been disproved already with a
prototype somewhere that failed? If not, a simple test app would not be
that hard to hack up. Maybe I'll see if I can do it during the week of
June 24 :)
thanks,
greg k-h
-
To unsubscribe from this list: send the line "unsubscribe linux-fsdevel" in
the body of a message to majordomo@vger.kernel.org
More majordomo info at http://vger.kernel.org/majordomo-info.html