On Fri, 2008-02-29 at 14:27 -0800, Casey Schaufler wrote:Actually we can expect interoperability with SELinux on both ends. With policy being the same on both ends it is completely valid to export a secctx which is a user readable text representation of a label and be able to use it on another selinux machine with the same policy. If I have a RHEL4 and RHEL 5 box with different policies then it is the job of the translation daemon to say I've gotten this label from this doi do I have a mapping for it. If yes translate it into my doi. If not reject it. This property is really no different from a user or group and I don't see anyone suggesting we start storing those in xattrs instead of recommended attrs. You need to give me a specific example of why if I have policy A on both ends on an SELinux box that a secctx isn't the same on both boxes. --
| Paul Jackson | Re: cpuset-remove-sched-domain-hooks-from-cpusets |
| James Bottomley | Re: Announce: Linux-next (Or Andrew's dream :-)) |
| David Miller | Slow DOWN, please!!! |
| Masami Hiramatsu | Re: [RFC PATCH v4] Unified trace buffer |
git: | |
| Gerrit Renker | [PATCH 27/37] dccp: Integration of dynamic feature activation - part 2 (server side) |
| Parag Warudkar | Re: 2.6.29-rc3: tg3 dead after resume |
| Jarek Poplawski | [PATCH] pkt_sched: Destroy gen estimators under rtnl_lock(). |
