> > I know there are a few cases, where filesystems call vfs_foo()
Maybe. I know precious little about this security thing, so I won't
argue about it's merits or faults. But:
a) I have a hunch that the security guys wouldn't like to see the
order between permission() and security_foo() changed.
b) I fail to see how moving functionality to callers would improve
things
Why?
Miklos
--