On Mon, 11 Jun 2007, Sean wrote:Ok, you are proposing throwing out all the label handling that SELinux does, including any caching. forgive me if I agree with the SELinux people that this is a very bad idea. I thought the userspace component was what you were proposing instead of doing the regex matching in the kernel. if this isn't it what exactly are you proposing? you don't want the regex matching in the kernel. you don't want a userspace component to do the regex matching when files are created or renamed. how exactly do you propose to figure out what should happen to a file when it is created or it (or a parent directory) is renamed? AA policies are defined in terms of regex expressions. you say that this should be able to be done on top of SELinux somehow without changing the policies. so somewhere, something needs to interpret the regex to see if it matches the path. this needs to be either kernel code or userspace code. you have ruled out kernel code and are now claiming that userspace isn't needed. David Lang -
| Arjan van de Ven | [Patch v2] Make PCI extended config space (MMCONFIG) a driver opt-in |
| Tilman Schmidt | git guidance |
| Vu Pham | Re: [Scst-devel] Integration of SCST in the mainstream Linux kernel |
| Greg KH | [GIT PATCH] driver core patches against 2.6.24 |
git: | |
| David Miller | Re: Git and GCC |
| Mike | I don't want the .git directory next to my code. |
| Steffen Prohaska | merge vs rebase: Is visualization in gitk the only problem? |
| David Kastrup | What is the idea for bare repositories? |
| Richard Stallman | Real men don't attack straw men |
| GVG GVG | ssh_exchange_identification: Connection closed by remote host |
| Falk Brockerhoff | ftp-proxy and no route to host issue |
| Pieter Verberne | Remove escape characters from file |
| Chuck Lever | Re: [bug?] tg3: Failed to load firmware "tigon/tg3_tso.bin" |
| David Miller | Re: [PATCH] pkt_sched: Destroy gen estimators under rtnl_lock(). |
| Stefan Richter | Re: [GIT]: Networking |
| jamal | Re: [LARTC] ifb and ppp |
