Sounds like a good idea. When i looked at the SECMARK code i could not
get my
head around the SELinux specific stuff, so i discarded the idea as to
complex.
For this to be complete i guess the CIPSO labels for SMACK would need
to be taken into account.
Far more than my quick and dirty approach, and probably more than i'm
the
right person to do it.
Il try to understand the inner workings of the SECMARK stuff tough.
I will come back to your other comments tomorrow.
Good to know.
I have not investigated further into that, but if there is some way to
match on CIPSO labels, there would be at least a vehicle to base this
on.
ok
Access control was actually not what i needed in this case.
This would in this case as far as i know actually be done in the SMACK
LSM.
I'm not sure how much it would make sense to base firewall decisions on
capability checks (i guess this is what you referring to).
Like decisions in the form of who/what may access a process in which
way.
Please correct me if i understood you wrong.
What i do with this match is just setting some CONNMARK and respectively
FWMARKS to make crazy routing rules for different kinds (marked
processes)
of my outgoing traffic based on them.
Regards
Tilman
--