--- Trond Myklebust <trond.myklebust@fys.uio.no> wrote:Twould appear that our mindsets are not in harmony. Oh, CXFS made mistakes, but I don't think this is one of them. But it appears we have sufficient fundimental differences that we'd agree on much of the list. This is a fun Friday afternoon exercise: - SELinux server, Smack client: Client sends "MyDogHasNoNose" to server. Server determines that is not a value secctx as far as it knows returns appropriate error. Client sends "sysadm_t:so,c1,2" (some understood SELinux context) to server. Server makes access check, goes ahead, even though the meaning of the secctx may be unrelated. On file creation, the file may get a secctx that the client would not expect. Client would deny access unless the client has a rule allowing that access. - Smack server, SELinux client: Client sends "sysadm_t:so,c1,2" to the server. Access checks are made with that string. New files will get created with that label. So long as there's a directory into which a process with that label can write it should work with Smack semantics. - So ... Either could be made to function somewhat if the Smack rules and labels got set properly. I can't claim to say that you couldn't set up the SELinux side to accomodate the Smack labels, but I don't think it would be easy if you can. I think it would be a really really bad idea for anyone to try this without both Stephen and me in the room. Dave should be there too, so he can watch if the atmosphere catches fire. I think that the general answer is that it wouldn't work, but with the fate of the universe at stake and a big budget hollywood production you could make something limp along. Casey Schaufler casey@schaufler-ca.com -- To unsubscribe from this list: send the line "unsubscribe linux-fsdevel" in the body of a message to majordomo@vger.kernel.org More majordomo info at http://vger.kernel.org/majordomo-info.html
| Linus Torvalds | Re: [PATCH 00/23] per device dirty throttling -v8 |
| Andi Kleen | [PATCH x86] [0/16] Various i386/x86-64 changes |
| serge | Re: 2.6.25-rc5-mm1 |
| Kamalesh Babulal | [BUG] Linux 2.6.25-rc2 - Kernel Ooops while running dbench |
git: | |
| Francis Moreau | Track /etc directory using Git |
| Abdelrazak Younes | Git-windows and git-svn? |
| Johan Herland | Re: People unaware of the importance of "git gc"? |
| Scott Chacon | git-scm.com |
| GVG GVG | ssh_exchange_identification: Connection closed by remote host |
| Richard Stallman | Real men don't attack straw men |
| Florin Andrei | firewall is very slow, something's wrong |
| qw er | OpenBSD sucks |
| David Miller | xfrm_state locking regression... |
| David Miller | [GIT]: Networking |
| Thomas Jarosch | Re: TCP connection stalls under 2.6.24.7 |
| Dave Jones | Re: odd RTL8139 quirk. |
