On Thu, 2008-02-28 at 18:48 -0500, Christoph Hellwig wrote:There are several things here. I've spoken to several people about this and the belief I've gotten from most of them is that a recommended attribute is how this is to be transported. The NFSv4 spec people will probably say that if you want xattr like functionality for NFSv4 use named attributes. For us this is not an option since we require semantics to label on create/open and the only way we can do this is by adding a recommended attribute. The create/open calls in NFSv4 takes a list of attributes to use on create as part of the request. I really don't see a difference between the security blob and the username/groupname that NFSv4 currently uses. Also there is a good chance that we will need to translate labels at some point (read future work). I can only speak for myself but honestly I've only seen Casey act confrontational to this idea from the beginning. There is absolutely nothing in here that is SELinux specific, tecnically its not even MAC specific. I said from the beginning that this was perhaps not the best name and we are willing to change it. There is nothing in this hook that wasn't in LSM before. This is almost identical functionality to what Adrian removed in 2.6.24. The only difference between this and security_inode_getsuffix is that this returns security.suffix and that the name is different. I don't have a SMACK box to test it on but I'm 99% sure that if Casey tried to use SMACK with this patch set that he would have labeled nfs working with SMACK. If it doesn't work with SMACK right now I'm willing to help him with that and even include it in the patch set. But spreading FUD about how we are including SELinux specific code in here is just that. Dave -- To unsubscribe from this list: send the line "unsubscribe linux-fsdevel" in the body of a message to majordomo@vger.kernel.org More majordomo info at http://vger.kernel.org/majordomo-info.html
| Ingo Molnar | Re: [PATCH 00/34] AMD IOMMU driver |
| Linus Torvalds | Linux 2.6.27-rc8 |
| Greg KH | [GIT PATCH] driver core patches against 2.6.24 |
| Ryan Hope | reiser4 for 2.6.27-rc1 |
git: | |
| Linus Torvalds | Re: [kernel.org users] [RFD] On deprecating "git-foo" for builtins |
| Jon Smirl | Re: VCS comparison table |
| Junio C Hamano | Re: [PATCH] Teach remote machinery about remotes.default config variable |
| Dmitry Kakurin | Re: Git on MSys (or how to make it easy for Windows users to compile git) |
| Octavian Purdila | race in skb_splice_bits? |
| Wolfgang Walter | Re: Kernel oops with 2.6.26, padlock and ipsec: probably problem with fpu state ch... |
| Ingo Molnar | Re: [bug, netconsole, SLUB] BUG skbuff_head_cache: Poison overwritten |
| Rick Jones | Re: 2.6.24 BUG: soft lockup - CPU#X |
| Richard Stallman | Real men don't attack straw men |
| chefren | Kuro5hin: OpenBSD Founder Theo deRaadt Has Conflict of Interest With AMD |
| Pieter Verberne | File collision while using pkg_add |
| Jason Dixon | Re: Hardware recommendation for firewalls (more than 4 NICs) |
