On Mon, 11 Jun 2007 02:33:30 -0700 (PDT) david@lang.hm wrote:Well presumably AA would be doing caching etc.. so that doesn't seem like a problem. The SELinux people seem to think that accepting AA into the kernel and supporting path based security at all is a mistake. I guess I forgive you for agreeing with them ;) No.. i've said quite a few times now that i'm not talking about calling out to userspace. The entire discussion of regex matching is a completely separate discussion. It's either the right thing to do, or not. But the same issues in regard to regex matching apply whether AA is built on top of SELinux or not. For whatever it's worth, i'll repeat again. The AA kernel extension would be associating paths with labels (using regex, or not). At that point all policy decisions would be enforced by SELinux using standard SELinux policy rules. The SELinux policy would be a translated version of the AA policy file. The translation could of course happen in userland. The net affect of all that... is that you get a version of SELinux which can be configured with the user friendly AA policy file format. And, files won't need to carry around security labels with them. I leave the debate about whether that's a good idea in general to others. But from what i can tell, it's the only significant difference between SELinux and AA. Depending on the way it was implemented, its conceivable that users could mix and match native SELinux policy with custom AA policies as they saw fit. Sean -
| Linus Torvalds | Linux 2.6.27-rc8 |
| Greg Kroah-Hartman | [PATCH 001/196] Chinese: Add the known_regression URI to the HOWTO |
| Mark Lord | Re: Linux 2.6.24-rc7 |
| Andi Kleen | Re: [PATCH] Version 3 (2.6.23-rc8) Smack: Simplified Mandatory Access Control Kernel |
git: | |
| Alex Riesen | Re: First cut at git port to Cygwin |
| Sverre Rabbelier | Git vs Monotone |
| Stephen R. van den Berg | [RFC] origin link for cherry-pick and revert |
| Len Brown | fatal: unable to create '.git/index': File exists |
| Richard Stallman | Real men don't attack straw men |
| GVG GVG | ssh_exchange_identification: Connection closed by remote host |
| Chris | Prolific USB-Serial Controller |
| Karl Sjödahl - dunceor | Re: Routerboard 532 Bounty |
| KOSAKI Motohiro | [bug?] tg3: Failed to load firmware "tigon/tg3_tso.bin" |
| Linus Torvalds | Re: [GIT]: Networking |
| Denys Fedoryshchenko | packetloss, on e1000e worse than r8169? |
| Ilpo Järvinen | Re: [bug] stuck localhost TCP connections, v2.6.26-rc3+ |
