--- Dave Quigley <dpquigl@tycho.nsa.gov> wrote:A completely reasonable LSM would be a discretionary time lock. The owner could set or unset the times when a file might be accessed. Stored as an xattr, but neither a label nor Mandatory Access Control. I propose this as an example of why the name maclabel is inappropriate, because in this case the data involved is neither. Please also consider that, as horrible as it may seem, an LSM could legitimately require more than one xattr. A proper Compartmented Mode Workstation, for example, might have a MAC label and an Information label, and as anyone familiar with the CMW spec will tell you, they have to be separate. Granted, the information label is only supposed to be used to indicate the actual sensitivity of information, but if it's available someone is going to use it programaticly. I'll grant you the xattr bit. The paradigm is* a security "blob" which is meaningfull only to the security module proper. This is what allows SELinux to use secids and Smack to toss around text strings. It's not MAC data and it's not an NFS label, it's private to the LSM. It makes a lot of sense to use an xattr to store a blob but, as the AppArmor people have been known espouse, it's not the only way. The blob could be referenced from a table using the inode number (it has been done on other systems and works fine) rather than an xattr, in which case the whole "name" may be meaningless. ---- * It was when the whole thing started out at least. Casey Schaufler casey@schaufler-ca.com --
| Greg Kroah-Hartman | [PATCH 004/196] Chinese: add translation of SubmittingPatches |
| James Bottomley | Re: Integration of SCST in the mainstream Linux kernel |
| Jeff Garzik | Re: [Patch v2] Make PCI extended config space (MMCONFIG) a driver opt-in |
| Chodorenko Michail | PROBLEM: Celeron Core |
git: | |
| Linus Torvalds | People unaware of the importance of "git gc"? |
| Johannes Schindelin | Re: Empty directories... |
| Jakub Narebski | Re: VCS comparison table |
| Sam Song | Re: Fwd: [OT] Re: Git via a proxy server? |
| J.W. Zondag | Dell PE1950 III - Perc 6i |
| Richard Stallman | Real men don't attack straw men |
| GVG GVG | ssh_exchange_identification: Connection closed by remote host |
| Anselm R. Garbe | OpenBSD 4.0 / Xorg -> vesa 1920x1200 widescreen resolution |
| Jim Winstead Jr. | Re: Root Disk/Book Disk Compatibility |
| Anselm Lingnau | File creation date in UNIX (was: Re: VMS) |
| Rafal Kustra (summer student) | mount |
| Nicholas Yue | Re: more on 486/33 weirdness |
