Re: [TOMOYO #9 (2.6.27-rc7-mm1) 1/6] LSM adapter functions.

Previous message: [thread] [date] [author]
Next message: [thread] [date] [author]
From: Casey Schaufler
Date: Tuesday, September 30, 2008 - 7:33 pm

Serge E. Hallyn wrote:

I have always believed that MAC should come first, then DAC, because
MAC may care if you can see the mode bits. The current DAC before MAC
is an artifact of the desire for the LSM to behave cleanly as a
strictly additional mechanism. From an ideal security perspective
MAC should be first, but the pragmatic DAC first isn't going to cause
too much grief. If Tomoyo wants to do what I think is the right thing,
well, it's OK with me.



--
Previous message: [thread] [date] [author]
Next message: [thread] [date] [author]

Messages in current thread:
[TOMOYO #9 (2.6.27-rc7-mm1) 1/6] LSM adapter functions., Kentaro Takeda, (Wed Sep 24, 2:03 am)
Re: [TOMOYO #9 (2.6.27-rc7-mm1) 1/6] LSM adapter functions., Serge E. Hallyn, (Thu Sep 25, 9:59 am)
Re: [TOMOYO #9 (2.6.27-rc7-mm1) 1/6] LSM adapter functions., Kentaro Takeda, (Thu Sep 25, 10:38 pm)
Re: [TOMOYO #9 (2.6.27-rc7-mm1) 1/6] LSM adapter functions., Serge E. Hallyn, (Fri Sep 26, 6:04 am)
Re: [TOMOYO #9 (2.6.27-rc7-mm1) 1/6] LSM adapter functions., Serge E. Hallyn, (Tue Sep 30, 8:45 am)
Re: [TOMOYO #9 (2.6.27-rc7-mm1) 1/6] LSM adapter functions., Stephen Smalley, (Tue Sep 30, 9:14 am)
Re: [TOMOYO #9 (2.6.27-rc7-mm1) 1/6] LSM adapter functions., Serge E. Hallyn, (Tue Sep 30, 9:23 am)
Re: [TOMOYO #9 (2.6.27-rc7-mm1) 1/6] LSM adapter functions., Casey Schaufler, (Tue Sep 30, 7:33 pm)
Re: [TOMOYO #9 (2.6.27-rc7-mm1) 1/6] LSM adapter functions., Valdis.Kletnieks, (Tue Sep 30, 10:05 pm)