login
Header Space

 
 

Re: [PATCH] Version 4 (2.6.23-rc8-mm2) Smack: Simplified Mandatory Access Control Kernel

Score:
Previous message: [thread] [date] [author]
Next message: [thread] [date] [author]
To: Casey Schaufler <casey@...>
Cc: <torvalds@...>, <linux-security-module@...>, <linux-kernel@...>, <akpm@...>, <paul.moore@...>
Date: Wednesday, October 3, 2007 - 1:52 pm

On Wed, Oct 03, 2007 at 10:21:08AM -0700, Casey Schaufler wrote:

Of course you can mount it more than once.  Just bind the sucker and you
are done.
 

Any more than having /tmp replaced with a symlink?


_What_ userland intervention?  Mounting stuff under /smack/tmp and not under
your /moldy?  Having /tmp replaced with symlink to /smack/tmp.link instead
of replacing it with a symlink to /smack/tmp?

Absolute paths in that kind of thing are _wrong_.  You know where the things
are on your fs.  You don't know if anything else will be visible, let alone
whether it will be at the same place in all chroots or namespaces.  And no,
you _can't_ make sure that fs is visible only in one place.  No fs can or
has any business even trying.
-
Previous message: [thread] [date] [author]
Next message: [thread] [date] [author]

Messages in current thread:
Re: [PATCH] Version 4 (2.6.23-rc8-mm2) Smack: Simplified Man..., Al Viro, (Wed Oct 3, 1:52 pm)
speck-geostationary