On Thu, 2008-02-28 at 11:23 -0800, Casey Schaufler wrote:Casey, you aren't listening (why am I surprised?). This is an interface to be used by NFS to get information from the security module. The information desired is specific to the MAC labeling functionality in NFSv4 that is being proposed. That functionality is MAC specific (necessarily so, just like the ACL functionality is ACL specific). We are hiding the SELinux-specific bits behind the LSM interface, and non-MAC LSMs are free to return NULL in order to indicate that they don't support MAC labeling. We do NOT want the capability module to return its security blob here, or any other non-MAC LSM - it will yield the wrong semantics for the NFS MAC support. In any event, I don't think we need your permission. -- Stephen Smalley National Security Agency -- To unsubscribe from this list: send the line "unsubscribe linux-fsdevel" in the body of a message to majordomo@vger.kernel.org More majordomo info at http://vger.kernel.org/majordomo-info.html
| Naveen Gupta | Re: [PATCH] cgroup: limit block I/O bandwidth |
| Chuck Ebbert | Why do so many machines need "noapic"? |
| Greg KH | [GIT PATCH] driver core patches against 2.6.24 |
| Ingo Molnar | Re: 2.6.24-rc6-mm1 |
git: | |
| Andy Parkins | svn:externals using git submodules |
| Linus Torvalds | Be more careful about updating refs |
| Wink Saville | Using git with Eclipse |
| Shawn O. Pearce | [JGIT PATCH 0/5] Patch parsing API |
| Steve Shockley | Re: Real men don't attack straw men |
| Laurent CARON | IPSEC VPN between OpenBSD and Linux (OpenSwan) |
| Beavis | mutiple pptp pass-through PF |
| GVG GVG | ssh_exchange_identification: Connection closed by remote host |
| Jarek Poplawski | Re: [PATCH] pkt_sched: Destroy gen estimators under rtnl_lock(). |
| Gerrit Renker | [PATCH 36/37] dccp: Initialisation and type-checking of feature sysctls |
| Hannes Eder | [PATCH 19/27] drivers/net/usb: fix sparse warnings: make symbols static |
| Arjan van de Ven | Re: [GIT]: Networking |
