On Thu, 2008-02-28 at 20:00 -0500, Christoph Hellwig wrote:Possibly I'm missing something, but if I'm implementing a security module that has any security attribute at all, e.g. capability module with security.capability, and I see a hook called "get_security_blob" or "get_security_attr" or the like, I'll implement that hook and return my attribute there. Which in turn will _break_ the labeled NFS functionality because it is expecting a MAC label specifically. The whole point here is that we do not want modules like capability to return their security attributes here, because this is to support labeled NFS functionality in support of enforcing MAC. I don't especially care about the hook name per se, but the interface (whatever it may be) needs to convey the proper semantics, and the semantics truly are MAC specific (and should be). -- Stephen Smalley National Security Agency -- To unsubscribe from this list: send the line "unsubscribe linux-fsdevel" in the body of a message to majordomo@vger.kernel.org More majordomo info at http://vger.kernel.org/majordomo-info.html
| Renato S. Yamane | Error -71 on device descriptor read/all |
| Stoyan Gaydarov | From 2.4 to 2.6 to 2.7? |
| Rafael J. Wysocki | 2.6.27-rc4-git1: Reported regressions from 2.6.26 |
| Adrian Bunk | Re: 463 kernel developers missing! |
git: | |
| Mike Hommey | Re: Minor annoyance with git push |
| Ken Pratt | pack operation is thrashing my server |
| Elijah Newren | Trying to use git-filter-branch to compress history by removing large, obsolete bi... |
| Wink Saville | Resolving conflicts |
| Daniel Andersson | Re: rtorrent + OpenBSD = freeze |
| Pieter Verberne | File collision while using pkg_add |
| Nick Guenther | Re: Real men don't attack straw men |
| Michael | Virtual interface |
| Jim Winstead Jr. | Re: Root Disk/Book Disk Compatibility |
| Theodore Ts'o | Re: demand paging: proposal |
| Ian Jackson | RESULT: comp.os.linux.announce passes 479:131, others fail |
| Brandon S. Allbery | Re: mkdir says "no space left on device" and more problems... |
