--- Stephen Smalley <sds@tycho.nsa.gov> wrote:I think that I am listening, and I appologize for doing such a poor job of getting my view on the across. Do you understand that if the functionality being proposed is specific to a particular file system it ought to be contained in that file system, not proposed as a part of the general purpose interface? The ACL funtionality over NFS could be done using general interfaces, and there are examples (e.g. Irix) where it has been done. I understand the rationale for the current implementation while disagreeing with that rationale. Further, there is a major difference between ACLs and a legitimate LSM (for MAC or DAC) in that ACLs are a change to the Linux access control scheme (they interact with the mode bits) whereas a legitimate LSM is strictly additional restrictions. I should hope then that your SELinux specific NFS server should look at the name presented and treat it appropriately. You're correct, you don't. You can propose anything you like. Don't take my criticisms personally, but I think you're wrong on this one. I don't like to see this unnecessary limitation, the kind that could haunt the code base for years, when it seems pretty obvious that it could be better. Casey Schaufler casey@schaufler-ca.com --
| Arnd Bergmann | SCHED_IDLE documentation |
| david | Re: limits on raid |
| Jan Engelhardt | Re: [PATCH] CodingStyle: multiple updates |
| Ingo Molnar | Re: Rescheduling interrupts |
git: | |
| Russ Brown | git-svn: Branching clarifications |
| Sam Song | Fwd: [OT] Re: Git via a proxy server? |
| Junio C Hamano | Re: More precise tag following |
| Pierre Habouzit | Re: People unaware of the importance of "git gc"? |
| Michael | Virtual interface |
| Stijn | Re: libiconv problem |
| Stefan Beke | mail dovecot: pipe() failed: Too many open files |
| Amaury De Ganseman | "ping: sendto: No buffer space available" when using bittorrent or another p2p |
| Jim Winstead Jr. | Re: Root Disk/Book Disk Compatibility |
| Darren Senn | Re: Elm |
| Seung-Chul Woo | Is it possible to mount GNU HURD file system as DOS in SLS? |
| David Willmore | Re: Intel, the Pentium and Linux |
