On Tuesday 05 August 2008 11:00:31 pm Casey Schaufler wrote:I still don't understand how that is any different from a file or some other resource, local or remote. Assuming a single security label (tag, mark, mode, etc.) on an entity on which you wish to apply an access control decision the problem boils down to how do you internalize the security label in such a way that it can be useful for the security mechanism(s). In the case of a single LSM you do this once, in the case of multiple, stacked LSMs you do this multiple times. With multiple security markings on an entity then you have to decide if you want to consider every marking at each LSM instance, or a subset. The complexity in this case does go up dramatically, but I think the key point for our discussion is that it doesn't matter if the entity is a file or a packet. Once again, these points apply equally to files as they do to packets. -- paul moore linux @ hp --
| Joe Perches | [PATCH 143/148] include/asm-x86/vm86.h: checkpatch cleanups - formatting only |
| Linus Torvalds | Re: Back to the future. |
| Greg Kroah-Hartman | [PATCH 004/196] Chinese: add translation of SubmittingPatches |
| Trent Piepho | [PATCH] [POWERPC] Improve (in|out)_beXX() asm code |
git: | |
| David Miller | Re: [PATCH] pkt_sched: Destroy gen estimators under rtnl_lock(). |
| Gerrit Renker | [PATCH 15/37] dccp: Set per-connection CCIDs via socket options |
| David Miller | [GIT]: Networking |
| Linus Torvalds | Re: iptables very slow after commit 784544739a25c30637397ace5489eeb6e15d7d49 |
