login
Header Space

 
 

Re: [RFC]Introduce generalized hooks for getting and setting inode secctx v3

Score:
Previous message: [thread] [date] [author]
Next message: [thread] [date] [author]
To: Stephen Smalley <sds@...>, <casey@...>
Cc: David P. Quigley <dpquigl@...>, <chrisw@...>, <jmorris@...>, <hch@...>, <viro@...>, <selinux@...>, <linux-security-module@...>, <linux-fsdevel@...>, <nfsv4@...>
Date: Wednesday, March 19, 2008 - 11:11 am

--- Stephen Smalley <sds@tycho.nsa.gov> wrote:


Oh, cut the crap. What part of my explainations don't you understand?

I understand the functionality. That is not my point. My point is
that inode_notifysecctx() explicitly prohibits the LSM from providing
integrity of the security attributes by introducing a differentiation
between the "in-core" and "on-disk" values, and making it explicit
that the one is set, but not the other.

Clearly this is the direction you intend to go. Have fun with it.
I've raised the issue, y'all aren't seeing it. Maybe I'm wrong,
it has happened before.


Yes indeed.

Thank you.


Casey Schaufler
casey@schaufler-ca.com
--
To unsubscribe from this list: send the line "unsubscribe linux-fsdevel" in
the body of a message to majordomo@vger.kernel.org
More majordomo info at  http://vger.kernel.org/majordomo-info.html
Previous message: [thread] [date] [author]
Next message: [thread] [date] [author]

Messages in current thread:
Re: [RFC]Introduce generalized hooks for getting and setting..., Casey Schaufler, (Wed Mar 19, 11:11 am)
speck-geostationary