Re: [PATCH BUGFIX -v2 -rc4] Smack: Respect 'unlabeled' netlabel mode

!MAILaRCHIVE_VOTE_RePLACE
Previous message: [thread] [date] [author]
Next message: [thread] [date] [author]
To: Ahmed S. Darwish <darwish.07@...>, Casey Schaufler <casey@...>, Paul Moore <paul.moore@...>
Cc: <linux-security-module@...>, LKML <linux-kernel@...>, <netdev@...>, Andrew Morton <akpm@...>
Date: Friday, May 30, 2008 - 7:45 pm

--- "Ahmed S. Darwish" <darwish.07@gmail.com> wrote:


This is truely awful. I suggest that instead of doing this
locking you disallow changes to the ambient label if the
nltype is not a well handled type, that is, CIPSO. The overhead
you're introducing to handle a case that will cause the system
to be pretty well useless (if ambient isn't the floor label
your system isn't going to work very well) seems ill advised.



Casey Schaufler
casey@schaufler-ca.com
--
Previous message: [thread] [date] [author]
Next message: [thread] [date] [author]

Messages in current thread:
[PATCH BUGFIX -rc4] Smack: Respect 'unlabeled' netlabel mode, Ahmed S. Darwish, (Fri May 30, 7:36 pm)
Re: [PATCH BUGFIX -v2 -rc4] Smack: Respect 'unlabeled' netla..., Casey Schaufler, (Fri May 30, 7:45 pm)