--- James Morris <jmorris@namei.org> wrote:To counter clarify: You are saying two things: 1. The policy always ensures a safe label. 2. Files can be relabeled in a reasonable and timely manner. I have no questions about 2. It's a hack, but you've already acknowledged that and it will work, allowing for some potential cases where someone is overeager about getting a file-in-transition. Regarding 1: This is a founding premise of the arguement, that the "policy" is written correctly such that there is no case where a file gets created with an unsafe label. Given the external nature of the policy, and the number of attributes used within the policy, and the overall sophistication of the policy mechanism, how does one ... a. know that a label is "safe" b. know that a file will get a "safe" label c. know that the policy is "correctly" written as required The question is not if fixxerupperd can set things right. The question is about the properly written policy that is required to make the mechanism worth discussing. De-nial. If you already have an in-kernel labeling scheme that you trust to make the world safe until you get around to doing the labeling externally you can argue that it's good enough. But, to quote Cinderella's Stepmother, "I said "if"". Casey Schaufler casey@schaufler-ca.com - To unsubscribe from this list: send the line "unsubscribe linux-fsdevel" in the body of a message to majordomo@vger.kernel.org More majordomo info at http://vger.kernel.org/majordomo-info.html
| David Miller | Slow DOWN, please!!! |
| KAMEZAWA Hiroyuki | Re: 2.6.22-rc1-mm1 |
| Steven Rostedt | [RFC PATCH 1/3] Unified trace buffer |
| Steven Rostedt | [RFC PATCH 0/6] Convert all tasklets to workqueues |
git: | |
| Peter Klavins | Re: CRLF problems with Git on Win32 |
| J. Bruce Fields | Re: Git User's Survey 2007 unfinished summary continued |
| Linus Torvalds | Re: VCS comparison table |
| Junichi Uekawa | Re: [ANNOUNCE] GIT 1.5.4 |
| Arjan van de Ven | Re: [GIT]: Networking |
| Rémi | [PATCH 0/6] [RFC] Phonet pipes protocol (v2) |
| Jarek Poplawski | Re: [PATCH] pkt_sched: Destroy gen estimators under rtnl_lock(). |
| Jozsef Kadlecsik | Re: TCP connection stalls under 2.6.24.7 |
| Richard Stallman | Real men don't attack straw men |
| Rogier Krieger | Re: bcw(4) is gone |
| Leon Dippenaar | New tcp stack attack |
| Brandon Lee | DELL PERC 5iR slow performance |
| high memory | 6 hours ago | Linux kernel |
| semaphore access speed | 9 hours ago | Applications and Utilities |
| the kernel how to power off the machine | 10 hours ago | Linux kernel |
| Easter Eggs in windows XP | 12 hours ago | Windows |
| Shared swap partition | 13 hours ago | Linux general |
| Root password | 13 hours ago | Linux general |
| Where/when DNOTIFY is used? | 15 hours ago | Linux kernel |
| How to convert Linux Kernel built-in module into a loadable module | 18 hours ago | Linux kernel |
| Linux 2.6.24 and I/O schedulers | 18 hours ago | Linux kernel |
| USB Driver -- Interrupt Polling -- A Little Help Please | 1 day ago | Linux general |
