Re: [PATCH BUGFIX -rc4] Smack: Respect 'unlabeled' netlabel mode

!MAILaRCHIVE_VOTE_RePLACE
Previous message: [thread] [date] [author]
Next message: [thread] [date] [author]
To: Ahmed S. Darwish <darwish.07@...>, Casey Schaufler <casey@...>, Paul Moore <paul.moore@...>
Cc: <linux-security-module@...>, LKML <linux-kernel@...>, <netdev@...>, Andrew Morton <akpm@...>
Date: Friday, May 30, 2008 - 7:10 pm

--- "Ahmed S. Darwish" <darwish.07@gmail.com> wrote:


To date the behavior of a Smack system running with nltype
unlabeled has been carefully undefined. The way you're defining
it will result in a system in which only processes running with
the ambient label will be able to use sockets, unless I'm reading
the code incorrectly. This seems like "correct" behavior, but
I don't think it is what those who've tried it would expect.


Casey Schaufler
casey@schaufler-ca.com
--
Previous message: [thread] [date] [author]
Next message: [thread] [date] [author]

Messages in current thread:
[PATCH BUGFIX -rc4] Smack: Respect 'unlabeled' netlabel mode, Ahmed S. Darwish, (Fri May 30, 7:36 pm)
Re: [PATCH BUGFIX -rc4] Smack: Respect 'unlabeled' netlabel ..., Casey Schaufler, (Fri May 30, 7:10 pm)