hi,i don't think splitting securelevel is a good way to achieve fine-grained control. (see below) TN mentions KAUTH_VNODE_WRITE_SECURITY/KAUTH_VNODE_NOIMMUTABLE, which is what we want, i guess. yes, i agree it's a trade-off among some kind of cleaness, efficiency, etc. - performance critical scopes should be small as far as possible. - don't care much about others. a possible concern; in future, we might introduce a performance critical operation which semantically fits one of scopes which is not performance critical today. i don't think "tcb" is a good idea because some aspects of securelevel have more appropriate scopes. and we already have "generic" scope for misc operations. i think one of the points of securelevel is being "a simple system global knob". if you want fine-grained control, it shouldn't be done by splitting securelevel, IMO. you can have both of securelevel listener and fine-graind access control listener. anyway, we need to factor out a set of operations/scopes necessary for suser and securelevel. ie. non trivial work :) maybe you can use ISSUSER-like temporary placeholder for some aspects of securelevel which don't have approrpriate scopes for now. i'm not sure if it's much better than direct manipulation of securelevel variable, tho. YAMAMOTO Takashi
| Karl Meyer | PROBLEM: 2.6.23-rc "NETDEV WATCHDOG: eth0: transmit timed out" |
| David Miller | Slow DOWN, please!!! |
| Mark Fasheh | [PATCH 0/39] Ocfs2 updates for 2.6.28 |
| Bart Van Assche | Integration of SCST in the mainstream Linux kernel |
git: | |
| Shawn O. Pearce | Re: pack operation is thrashing my server |
| Pierre Habouzit | git send-email improvements |
| Matthieu Moy | git push to a non-bare repository |
| Shawn O. Pearce | libgit2 - a true git library |
| Elad Efrat | Integrating securelevel and kauth(9) |
| Hubert Feyrer | Re: Compressed vnd handling tested successfully |
| Lord Isildur | Re: Fork bomb protection patch |
| Matt Thomas | Re: FFS journal |
| Will Maier | cron doesn't run commands in /etc/crontab? |
| Richard Stallman | Real men don't attack straw men |
| Harald Dunkel | Re: Packet Filter: how to keep device names on hardware failure? |
| Jordi Espasa Clofent | Resolving dependencies with pkg_add |
| Question on swap as ramdisk partition | 1 hour ago | Linux kernel |
| Netfilter kernel module | 11 hours ago | Linux kernel |
| serial driver xmit problem | 14 hours ago | Linux kernel |
| Why Windows is better than Linux | 14 hours ago | Linux general |
| How can I see my kernel messages in vt12? | 21 hours ago | Linux kernel |
| Grub | 1 day ago | Linux general |
| vmalloc_fault handling in x86_64 | 1 day ago | Linux kernel |
| epoll_wait()ing on epoll FD | 1 day ago | Linux kernel |
| Framebuffer in x86_64 causes problems to multiseat | 1 day ago | Linux kernel |
| Difference between 2.4 and 2.6 regarding thread creation | 2 days ago | Linux general |
