Re: [PATCH 00/16] Permit filesystem local caching [try #3]

Previous message: [thread] [date] [author]
Next message: [thread] [date] [author]
From: Casey Schaufler
Date: Monday, August 13, 2007 - 8:42 am

--- Stephen Smalley <sds@tycho.nsa.gov> wrote:




LSM stacking has always been contentious and I don't see
that it addresses the issue, which is changing the data used
by an LSM, not the LSM itself.


The objection centers around exposing LSM specific data outside
the LSM, and it applies to either secids or blobs, really. If you
need this information outside the LSM odds are good that what you're
using it for is going to be LSM specific, and hence should be inside
the LSM. I admit to two gray areas, audit and system service tasks
such as the two cited here. I like simplicity and find the single
security_act_as() interface attractive for the latter case.


Casey Schaufler
casey@schaufler-ca.com
-
Previous message: [thread] [date] [author]
Next message: [thread] [date] [author]

Messages in current thread:
[PATCH 00/16] Permit filesystem local caching [try #3], David Howells, (Fri Aug 10, 9:04 am)
[PATCH 14/16] NFS: Use local caching [try #3], David Howells, (Fri Aug 10, 9:06 am)
[PATCH 16/16] NFS: Display local caching state [try #3], David Howells, (Fri Aug 10, 9:06 am)
Re: [PATCH 00/16] Permit filesystem local caching [try #3], Casey Schaufler, (Fri Aug 10, 3:13 pm)
Re: [PATCH 00/16] Permit filesystem local caching [try #3], Casey Schaufler, (Sat Aug 11, 8:56 am)
Re: [PATCH 00/16] Permit filesystem local caching [try #3], Stephen Smalley, (Mon Aug 13, 6:01 am)
Re: [PATCH 00/16] Permit filesystem local caching [try #3], Casey Schaufler, (Mon Aug 13, 6:46 am)
Re: [PATCH 00/16] Permit filesystem local caching [try #3], Stephen Smalley, (Mon Aug 13, 6:50 am)
Re: [PATCH 00/16] Permit filesystem local caching [try #3], Stephen Smalley, (Mon Aug 13, 7:57 am)
Re: [PATCH 00/16] Permit filesystem local caching [try #3], Casey Schaufler, (Mon Aug 13, 8:10 am)
Re: [PATCH 00/16] Permit filesystem local caching [try #3], Casey Schaufler, (Mon Aug 13, 8:42 am)
Re: [PATCH 00/16] Permit filesystem local caching [try #3], Casey Schaufler, (Mon Aug 13, 9:20 am)
Re: [PATCH 00/16] Permit filesystem local caching [try #3], Casey Schaufler, (Mon Aug 13, 9:58 am)
Re: [PATCH 00/16] Permit filesystem local caching [try #3], David Howells, (Mon Aug 13, 12:52 pm)
Re: [PATCH 00/16] Permit filesystem local caching [try #3], Casey Schaufler, (Mon Aug 13, 2:44 pm)
Re: [PATCH 00/16] Permit filesystem local caching [try #3], Casey Schaufler, (Tue Aug 14, 8:53 am)
Re: [PATCH 00/16] Permit filesystem local caching [try #3], Stephen Smalley, (Tue Aug 14, 10:42 am)
Re: [PATCH 00/16] Permit filesystem local caching [try #3], Stephen Smalley, (Tue Aug 14, 10:50 am)
Re: [PATCH 00/16] Permit filesystem local caching [try #3], David Howells, (Tue Aug 14, 10:58 am)
Re: [PATCH 00/16] Permit filesystem local caching [try #3], Casey Schaufler, (Wed Aug 15, 9:30 am)