Re: [PATCH] Version 4 (2.6.23-rc8-mm2) Smack: Simplified Mandatory Access Control Kernel

!MAILaRCHIVE_VOTE_RePLACE
Previous message: [thread] [date] [author]
Next message: [thread] [date] [author]
To: Casey Schaufler <casey@...>
Cc: <torvalds@...>, <linux-security-module@...>, <linux-kernel@...>, <akpm@...>, <paul.moore@...>
Date: Wednesday, October 3, 2007 - 4:57 pm

On Wed, Oct 03, 2007 at 12:51:08PM -0700, Casey Schaufler wrote:

And your point is?  If you don't use it, you get exact same complexity
in both setups.
 

Sigh...  So put the binding into fstab and be done with that.
 

Right now the main objection is about your lack of ability to read.  Which
part of "it can be mounted in different chroots/namespaces, therefore
having absolute paths doesn't work" is too hard to understand?

No, it's not about having a default.  It's about keeping an absolute pathname
in virtual fs, having all instances autosoddingmatically sharing it _and_
having change attempt in any instance automatically affect all of them.
If you have that kind of sharing, don't pretend that your mechanism really
allows absolute pathnames.
-
Previous message: [thread] [date] [author]
Next message: [thread] [date] [author]

Messages in current thread:
Re: [PATCH] Version 4 (2.6.23-rc8-mm2) Smack: Simplified Man..., Al Viro, (Wed Oct 3, 4:57 pm)