Re: [PATCH 01/11] Security: Add hook to get full maclabel xattr name

Previous message: [thread] [date] [author]
Next message: [thread] [date] [author]
From: Dave Quigley
Date: Thursday, February 28, 2008 - 6:33 pm

On Thu, 2008-02-28 at 17:47 -0800, Casey Schaufler wrote:

You might be right that Linux and LSM are better served by this, but
this has to be used by more than just Linux. Solaris has the new FMAC
initiative (The F is silent) which will probably want to use this as
well. SEBSD/SEDarwin also has a use for this and they have a MAC label
concept in their OS with a system call for getting/setting it. 


I'm not about to get between him and Christoph :)


It seems your argument is against using xattrs. Regardless of this hook
the 0 xattr LSM is still borked by this. security_inode_getsecurity(...,
suffix, ...). It is assumed that the fundamental function for getting
security information takes an xattr suffix. Don't bother responding to
this email eventually you will get to the one where I agree with you on
some points.


Keep reading your emails :)

--
To unsubscribe from this list: send the line "unsubscribe linux-fsdevel" in
the body of a message to majordomo@vger.kernel.org
More majordomo info at  http://vger.kernel.org/majordomo-info.html
Previous message: [thread] [date] [author]
Next message: [thread] [date] [author]

Messages in current thread:
RFC Labeled NFS Initial Code Review, David P. Quigley, (Wed Feb 27, 3:11 pm)
[PATCH 03/11] VFS: Add security label support to *notify, David P. Quigley, (Wed Feb 27, 3:11 pm)
[PATCH 06/11] SELinux: Add new labeling type native labels, David P. Quigley, (Wed Feb 27, 3:11 pm)
[PATCH 09/11] NFS: Client implementation of Labeled-NFS, David P. Quigley, (Wed Feb 27, 3:11 pm)
[PATCH 11/11] NFSD: Server implementation of MAC Labeling, David P. Quigley, (Wed Feb 27, 3:11 pm)
Re: RFC Labeled NFS Initial Code Review, Dave Quigley, (Wed Feb 27, 5:48 pm)
Re: RFC Labeled NFS Initial Code Review, Dave Quigley, (Wed Feb 27, 6:23 pm)
Re: [PATCH 01/11] Security: Add hook to get full maclabel ..., Casey Schaufler, (Thu Feb 28, 12:23 pm)
Re: [PATCH 01/11] Security: Add hook to get full maclabel ..., Stephen Smalley, (Thu Feb 28, 12:30 pm)
Re: [PATCH 01/11] Security: Add hook to get full maclabel ..., Casey Schaufler, (Thu Feb 28, 12:59 pm)
Re: [PATCH 01/11] Security: Add hook to get full maclabel ..., Christoph Hellwig, (Thu Feb 28, 4:48 pm)
Re: [PATCH 03/11] VFS: Add security label support to *notify, Christoph Hellwig, (Thu Feb 28, 4:54 pm)
Re: [PATCH 03/11] VFS: Add security label support to *notify, Christoph Hellwig, (Thu Feb 28, 5:23 pm)
Re: [PATCH 01/11] Security: Add hook to get full maclabel ..., Christoph Hellwig, (Thu Feb 28, 5:39 pm)
Re: [PATCH 01/11] Security: Add hook to get full maclabel ..., Christoph Hellwig, (Thu Feb 28, 5:51 pm)
Re: [PATCH 01/11] Security: Add hook to get full maclabel ..., Christoph Hellwig, (Thu Feb 28, 6:00 pm)
Re: [PATCH 01/11] Security: Add hook to get full maclabel ..., Dave Quigley, (Thu Feb 28, 6:33 pm)
Re: [PATCH 01/11] Security: Add hook to get full maclabel ..., Trond Myklebust, (Thu Feb 28, 10:01 pm)
Re: [PATCH 01/11] Security: Add hook to get full maclabel ..., Trond Myklebust, (Thu Feb 28, 10:04 pm)
Re: [PATCH 01/11] Security: Add hook to get full maclabel ..., Casey Schaufler, (Fri Feb 29, 10:26 am)
Re: [PATCH 01/11] Security: Add hook to get full maclabel ..., Casey Schaufler, (Fri Feb 29, 10:46 am)
Re: [PATCH 01/11] Security: Add hook to get full maclabel ..., Casey Schaufler, (Fri Feb 29, 10:52 am)
Re: [PATCH 01/11] Security: Add hook to get full maclabel ..., Trond Myklebust, (Fri Feb 29, 11:28 am)
Re: [PATCH 01/11] Security: Add hook to get full maclabel ..., Casey Schaufler, (Fri Feb 29, 11:52 am)
Re: [PATCH 01/11] Security: Add hook to get full maclabel ..., Trond Myklebust, (Fri Feb 29, 12:50 pm)