On Sat, 9 Jun 2007 11:01:41 +0900 Tetsuo Handa <from-lsm@I-love.SAKURA.ne.jp> wrote:is trying to implement, is to do in one step what SELinux does in two steps; that is trying to combine labelling and enforcement into a single step. If this is so, then why can't it just feed its automatic labelling into SELinux enforcement code? That paper seems entirely focused on the automatic generation of policy, and doesn't seem to help the discussion along. For instance, there may be a way to implement AA on top of SELinux _without_ giving each and every file its own label. AA must have a function that decides the security rights for any given path in order to make its enforcement decisions. It must surely be able to deal with all those things you listed above (bind-mounts,hard links etc). So why can't those decisions be turned into labels that are fed into SELinux enforcement code? Sean. -
| Chuck Ebbert | Wanted: simple, safe x86 stack overflow detection |
| Alan Cox | Re: ndiswrapper and GPL-only symbols redux |
| Yinghai Lu | [PATCH 03/42] x86: remove irq_vectors_limits |
| Greg Kroah-Hartman | [PATCH 001/196] Chinese: Add the known_regression URI to the HOWTO |
git: | |
| しらいしななこ | Re: [ANNOUNCE] GIT 1.5.4 |
| Jan Wielemaker | git filter-branch --subdirectory-filter, still a mistery |
| Pierre Habouzit | [PATCH] guilt(1): Obvious bashisms fixed. |
| Christopher Faylor | Re: First cut at git port to Cygwin |
| Thilo Pfennig | OpenBSD project goals |
| Marco Peereboom | Re: Real men don't attack straw men |
| Daniel Hazelton | Re: Wasting our Freedom |
| Luke Bakken | Re: No Blob without Puffy |
| Julius Volz | [PATCHv3 19/24] IVPS: Disable sync daemon for IPv6 connections |
| Paul Moore | [RFC PATCH v4 04/14] selinux: Fix missing calls to netlbl_skbuff_err() |
| Dave Jones | odd RTL8139 quirk. |
| Patrick McHardy | [NET_SCHED 04/15]: act_api: use nlmsg_parse |
