> Serge E. Hallyn wrote:Traditional "talking by examples" is a good way and works in general, but not always right for this case (I mean "label or path" discussion. Yes, I've learned this from AppArmor thread. :) Agreed and I personally would love to stay discussions in this layer forgetting existing implementations, including my own project of TOMOYO Linux. The above summary of labels and names are very important, but I would like to "raise" the layer of discussion. The essence of MAC is limiting and restricting. My version of the MAC *issues* are as follows: - how to distinguish good(necessary) and bad(unnecessary) accesses - how to describe the rule (the most important result is a policy language) - how to keep Linux kernel aware of the rule and keep it safely - how to administrate the whole picture (with human error in mind) The first one belongs to a human responsible part and the remainders belong to implementations. Let me note, label vs. names issue resides in the implementation layer. How to describe rules imply "what is the natural way for human administrators" while keeping the Linux kernel implies "what is the most solid and trusted way for Linux". From the fact is Linux works with names and inodes, I'm pretty sure we will end up with some sort of hybrid system. From the above point of view, the option 2 which Stephen kindly showed quite *practical* to me, because it allows loose connection of the "namespace" and "inode". (If your initial is not S.S, my PNG diagram posted on April 10 might help to understand what I wrote here) BTW I'm attending the ELC2008. Hope to see and talk in peace with some of related people. :) Regards, Toshiharu Harada NTT DATA CORPORATION --
| Mikulas Patocka | LFENCE instruction (was: [rfc][patch 3/3] x86: optimise barriers) |
| Daniel J Blueman | time for TCP ECN defaulting to on? |
| Renato S. Yamane | Error -71 on device descriptor read/all |
| Zdenek Kabelac | Suspend to memory is freezing my machine |
git: | |
| Abdelrazak Younes | Git-windows and git-svn? |
| Giuseppe Bilotta | Re: gitweb and remote branches |
| Petr Baudis | repo.or.cz wishes? |
| Josh England | Re: cloning/pulling hooks |
| Reyk Floeter | Re: Real men don't attack straw men |
| Alexey Suslikov | OT: OpenBSD on Asus eeePC |
| Jernej Makovsek | How secure is OpenBSD really |
| Girish Venkatachalam | Ethernet jumbo frames? |
| Kim Phillips | [PATCH 0/5] fixups for mpc8360 rev. 2.1 erratum #2 (RGMII Timing) |
| Michael Grollman | Re: 8169 Intermittent ifup Failure Issue With RTL8102E Chipset in Intel's New D945... |
| Gerrit Renker | [PATCH 5/5] dccp: Tidy up setsockopt calls |
| Jeff Garzik | Re: [bug?] tg3: Failed to load firmware "tigon/tg3_tso.bin" |
