login
Header Space

 
 

Re: NFS/LSM: allow NFS to control all of its own mount options

Score:
Previous message: [thread] [date] [author]
Next message: [thread] [date] [author]
To: Christoph Hellwig <hch@...>
Cc: Eric Paris <eparis@...>, <linux-nfs@...>, selinux <selinux@...>, <linux-security-module@...>, <steved@...>, <jlayton@...>, <sds@...>, <casey@...>, <trond.myklebust@...>, <chuck.lever@...>, <linux-fsdevel@...>
Date: Tuesday, February 19, 2008 - 8:25 pm

On Tue, 19 Feb 2008, Christoph Hellwig wrote:


It's not so much a special case for NFS, just that NFS happens to use 
binary mount options.  So, I guess it could be put into a library for 
other potential filesystems with binary mount options.

To clarify:

The SELinux options are indeed filesystem independent, and the FS should 
really not need to be concerned at all with them.  For everything except 
NFS, we parse text options looking for context=, then use that value from 
within SELinux as the label for all files in the mount.

Previously, as Eric mentions, we were using a method initially approved by 
the NFS folk, where, for NFS, SELinux was peeking around inside the binary 
options.  We were then asked to change that so that NFS (or other 
binary-option FS) would obtain the values itself and call into LSM with 
them.  This is what Eric's latest patch enables (a previous patch 
installed the infrastructure for it).

While this code could be put into a library if desired, there is no need 
to make any changes for filesystems with text options (i.e. the general 
case).



- James
-- 
James Morris
<jmorris@namei.org>
-
To unsubscribe from this list: send the line "unsubscribe linux-fsdevel" in
the body of a message to majordomo@vger.kernel.org
More majordomo info at  http://vger.kernel.org/majordomo-info.html
Previous message: [thread] [date] [author]
Next message: [thread] [date] [author]

Messages in current thread:
Re: NFS/LSM: allow NFS to control all of its own mount options, Christoph Hellwig, (Tue Feb 19, 6:24 pm)
Re: NFS/LSM: allow NFS to control all of its own mount options, James Morris, (Tue Feb 19, 8:25 pm)
speck-geostationary