> Quoting Casey Schaufler (
casey@schaufler-ca.com):
> > ...
> > Good suggestion. In fact, that is exactly how I approached my
> > first two attempts at the problem. What you get if you take that
> > route is an imposing infrastructure that has virually nothing
> > to do and that adds no value to the solution. Programming to the
> > LSM interface, on the other hand, allowed me to drastically reduce
> > the size and complexity of the implementation.
>
> (tongue-in-cheek)
>
> No no, everyone knows you don't build simpler things on top of more
> complicated ones, you go the other way around. So what he was
> suggesting was that selinux be re-written on top of smack.
>
> :)