--- Stephen Smalley <sds@tycho.nsa.gov> wrote:I can see how it's being used just fine, thank you. If you only want this interface for SELinux put it in SELinux. Don't clutter up the LSM with it. If it's an LSM interface it should be potentially useful for any and all LSMs, be they label based or not, MAC or DAC. Even within a label based MAC scheme it may not be sensible, given that a MAC scheme could use multiple xattrs (e.g. a B&L sensitivity label and a Biba integrity label) to store its blob. If what you want in LSM terms is a name to give the blob make your interface be security_blob_name(). The LSM can deal with this as it sees fit, and NFS can determine if it's a blob that it wants to deal with independently. Such an interface could even support stacking should that ever come about. LSM is not supposed to be only for MAC and it's not supposed to be only for label based schemes. It's supposed to be for additional security restrictions. Providing an interface that should be generally applicable with a name that constrains it to a specific subset of those schemes is wrong. Casey Schaufler casey@schaufler-ca.com -- To unsubscribe from this list: send the line "unsubscribe linux-fsdevel" in the body of a message to majordomo@vger.kernel.org More majordomo info at http://vger.kernel.org/majordomo-info.html
| Roman Zippel | Re: [announce] CFS-devel, performance improvements |
| Andrew Morton | 2.6.23-rc4-mm1 |
| Oliver Pinter | Re: x86: 4kstacks default |
| Greg Kroah-Hartman | [PATCH 005/196] Chinese: add translation of SubmittingDrivers |
git: | |
| Ken Pratt | pack operation is thrashing my server |
| Johannes Schindelin | Re: git on MacOSX and files with decomposed utf-8 file names |
| martin f krafft | confused about preserved permissions |
| Sean | Re: VCS comparison table |
| Richard Stallman | Real men don't attack straw men |
| Brandon Lee | DELL PERC 5iR slow performance |
| Chris Tankersley | Dell PERC 3/Di - No Disks Found |
| Sunnz | How do I configure sendmail? |
| Mark Lord | Re: 2.6.25-rc8: FTP transfer errors |
| Jeff Kirsher | [NET-NEXT PATCH 0/9] e1000: update and cleanups |
| Dâniel | Re: [PATCH] tcp FRTO: in-order-only "TCP proxy" fragility workaround |
| David Miller | Re: sockets affected by IPsec always block (2.6.23) |
