On Fri, Aug 15, 2008 at 08:57:48AM -0400, Press, Jonathan wrote:
Sure, as long as we're very clear about the semantics of the bits. If
the bits are not persistent, but which get dropped if the inode is
every evicted from memory, and it's considered OK, or even desirable,
to rescan the file when it is brought back into memory, that may be
acceptable to the rubber gloves folks (make people go through lots
superflous of security scans, even when they are transfering betewen
flights --- security is always more important than passengers'
convenience!), but perhaps not to other applications such as file
indexers, who would view rescanning files that have already been
scanned, and not have been modified, as a waste of time, battery, CPU
and disk bandwidth, etc.
As I understand it, the TALPA proposal had non-persistent
clean/dirty/infected bits.
- Ted
--