On Fri, 2008-02-29 at 10:52 -0800, Casey Schaufler wrote:The problem isn't that of supporting the naive user xattr model: we can almost do that within the existing 'named attribute' model of NFSv4. The problem is that of supporting the arbitrary "security metadata" that are allowed to have side-effects on the system behaviour, and that we appear to have thought was a good idea to overload onto the xattr interface. In the case of maclabels, where the "side-effect" is to describe and enable extra access control rules, then you have the potential for setting people up with a major interoperability problem. Using a dedicated interface for it instead of overloading a Linux-style xattr interface allows you to limit the scope of the documentation problem that you would otherwise have. Trond --
| Vladislav Bolkhovitin | Re: Integration of SCST in the mainstream Linux kernel |
| Greg Kroah-Hartman | [PATCH 005/196] Chinese: add translation of SubmittingDrivers |
| Yinghai Lu | [PATCH 01/33] x86: add after_bootmem for 32bit |
| Joerg Roedel | [PATCH] AMD IOMMU: replace to_pages macro with iommu_num_pages |
git: | |
| Jan Wielemaker | Re: git filter-branch --subdirectory-filter, still a mistery |
| Nguyễn Thái Ngọc Duy | [PATCH 01/14] Extend index to save more flags |
| davidk | Removing files |
| Guido Ostkamp | [PATCH] Fix "identifier redeclared" compilation error with SUN cc |
| David Miller | [GIT]: Networking |
| Lachlan Andrew | Re: [PATCH] tcp-illinois: incorrect beta usage |
| Julius Volz | [PATCHv2 RFC 01/25] IPVS: Add CONFIG_IP_VS_IPV6 option for IPv6 support |
| Mark Lord | Re: 2.6.25-rc8: FTP transfer errors |
| Richard Stallman | Real men don't attack straw men |
| Greg KH | Re: Free Linux Driver Development! |
| Marcos Laufer | dmesg IBM x3650 OpenBSD 4.3 |
| Mark Kettenis | Re: Random crashes with Intel D945GCLF2 |
