On Thu, 2008-04-10 at 14:57 +0900, Toshiharu Harada wrote:Definitely not always. I think the text above is self-explanatory; I'm not sure what the diagram adds. Also, Matthew Wilcox pointed out a third option that you ought to consider, and you can look to the example of audit filesystem watches there, which leverages inotify internally. If that isn't feasible for some reason, then option (2) should be fairly straightforward - you just define and insert some new security hooks in the callers where the vfsmount is already available. -- Stephen Smalley National Security Agency -- To unsubscribe from this list: send the line "unsubscribe netdev" in the body of a message to majordomo@vger.kernel.org More majordomo info at http://vger.kernel.org/majordomo-info.html
| Greg Kroah-Hartman | [PATCH 004/196] Chinese: add translation of SubmittingPatches |
| Bart Van Assche | Integration of SCST in the mainstream Linux kernel |
| Rafael J. Wysocki | 2.6.27-rc4-git1: Reported regressions from 2.6.26 |
| Pavel Roskin | ndiswrapper and GPL-only symbols redux |
git: | |
| Corey Minyard | [PATCH 3/3] Convert the UDP hash lock to RCU |
| David Miller | [GIT]: Networking |
| David Miller | Re: [PATCH] pkt_sched: Destroy gen estimators under rtnl_lock(). |
| Mark Smith | MACVLANs really best solution? How about a bridge with multiple bridge virtual int... |
