Re: [PATCH 02/14] LSM/SELinux: inode_{get,set,notify}secctx hooks to access LSM security context information.

!MAILaRCHIVE_VOTE_RePLACE
Previous message: [thread] [date] [author]
Next message: [thread] [date] [author]
To: David P. Quigley <dpquigl@...>
Cc: <hch@...>, <viro@...>, <casey@...>, <sds@...>, <matthew.dodd@...>, <trond.myklebust@...>, <bfields@...>, <linux-kernel@...>, <linux-fsdevel@...>, <linux-security-module@...>, <selinux@...>, <labeled-nfs@...>
Date: Tuesday, September 30, 2008 - 4:22 pm

Quoting David P. Quigley (dpquigl@tycho.nsa.gov):

Hmm, sorry, for all of these new hooks which you introduce, you do not
define empty cap_* versions and assign them when need in
security_fixup_ops().  But you unconditionally call them if
CONFIG_SECURITY=y.  So if you compile a kernel with CONFIG_SECURITY=y
but CONFIG_SECURITY_SELINUX=n, don't you hose your box?

--
Previous message: [thread] [date] [author]
Next message: [thread] [date] [author]

Messages in current thread:
Re: [PATCH 02/14] LSM/SELinux: inode_{get,set,notify}secctx ..., Serge E. Hallyn, (Tue Sep 30, 4:22 pm)