On Tue, Aug 05, 2008 at 01:21:01PM +0200, Helge Hafting wrote:That's fine, then the file is corrupted. It is when the "normal" program goes to load the file that we want to block and determine if we have a problem or not in the data. virus scanners are not a security model in the aspect of SELinux or SMACK. If they were, they would just use the LSM interface. virus scanners are interested in blocking "normal" programs from reading invalid data from disk before acting on it or executing it. thanks, greg k-h --
