On Mon, Oct 22, 2007 at 08:48:04PM -0400, Erez Zadok wrote:No, it's a matter of proper layering. We generally don't want modules like stackabke filesystems to call directly into methods but rather use proper highlevel VFS helpers to isolate them from details and possible changes. The move to out of line security_ helpers just put this on the radard. Sounds fine. The fix for security_file_ioctl is probably to either not do it at all or move it the call to security_file_ioctl into vfs_ioctl and get it by using that helper. I suspect most other security_ exports should be avoided similarly. I also suspect the whole issue of where and how-many times to call LSM methods for stackable filesystems is a huge can of worms and it might make sense to talk to the LSM folks about it. -
| david | Re: Dual-Licensing Linux Kernel with GPL V2 and GPL V3 |
| Eric Sandeen | Re: [RFC] Heads up on sys_fallocate() |
| Filippos Papadopoulos | Re: INITIO scsi driver fails to work properly |
| Greg KH | [GIT PATCH] driver core patches against 2.6.24 |
git: | |
| Gerrit Renker | [PATCH 27/37] dccp: Integration of dynamic feature activation - part 2 (server side) |
| David Miller | [GIT]: Networking |
| Jarek Poplawski | [PATCH take 2] pkt_sched: Protect gen estimators under est_lock. |
| Natalie Protasevich | [BUG] New Kernel Bugs |
