> > sorry again, can you privide a pointer?i was not sure if you were referring to the same thread, so i asked. i couldn't find any consensus about how to implement fine-grained control in the thread. i don't have any objection to implementing securelevel via kauth. however, i don't think splitting securelevel is really related to it. you can have listeners for fine-grained knobs, in addition to securelevel listener. because the former is not a securelevel anymore, it's reasonable to have separate listeners, IMO. at least i'm not happy, so "not everyone". do you mean my comments were pointless? sorry if so. yes, let's wait for more opinions. i meant it's ISSUSER-like just in the sense that it's a temporary placeholder. let me restate my opinions. - handling securelevel via kauth is fine. - in kauth world, securelevel should be implemented as listeners for appropriate scopes. - if you want fine-grained control ("multiple knobs"), it should be another listener(s). splitting securelevel is not a right way. (you might want to coalesce listeners to default one for performance. it's fine, but it doesn't change the logical structure, i think.) - i'm not sure if securelevel is a good target to shoot now. it's better to tackle suser() first. YAMAMOTO Takashi
| Martin Bligh | Re: Unified tracing buffer |
| Ingo Molnar | [announce] "kill the Big Kernel Lock (BKL)" tree |
| Con Kolivas | [PATCH] [RFC] sched: accurate user accounting |
| Bart Van Assche | Integration of SCST in the mainstream Linux kernel |
| Krzysztof Oledzki | Error: an inet prefix is expected rather than "0/0". |
| Wenji Wu | A Linux TCP SACK Question |
| Ramachandra K | [PATCH 11/13] QLogic VNIC: Driver utility file - implements various utility macros |
| Jay Cliburn | Re: atl1 64-bit => 32-bit DMA borkage (reproducible, bisected) |
git: | |
| Andrew Morton | Untracked working tree files |
| Pierre Habouzit | Re: libgit2 - a true git library |
| Nicolas Vilz 'niv' | git + ssh + key authentication feature-request |
| Martin Langhoff | Re: pack operation is thrashing my server |
| Steve B | SSH brute force attacks no longer being caught by PF rule |
| GVG GVG | ssh_exchange_identification: Connection closed by remote host |
| rancor | How to copy/pipe console buffert to file? |
| Richard Stallman | Real men don't attack straw men |
| Question on swap as ramdisk partition | 46 minutes ago | Linux kernel |
| Netfilter kernel module | 11 hours ago | Linux kernel |
| serial driver xmit problem | 14 hours ago | Linux kernel |
| Why Windows is better than Linux | 14 hours ago | Linux general |
| How can I see my kernel messages in vt12? | 20 hours ago | Linux kernel |
| Grub | 1 day ago | Linux general |
| vmalloc_fault handling in x86_64 | 1 day ago | Linux kernel |
| epoll_wait()ing on epoll FD | 1 day ago | Linux kernel |
| Framebuffer in x86_64 causes problems to multiseat | 1 day ago | Linux kernel |
| Difference between 2.4 and 2.6 regarding thread creation | 2 days ago | Linux general |
