Re: [PATCH] skb hooks (v.2)

From: Chris Wright (chrisat_private)
Date: Wed Jul 25 2001 - 17:59:33 PDT

  • Next message: Crispin Cowan: "Re: File descriptors: LSM should support them in phase 1."

    * James Morris (jmorrisat_private) wrote:
    > Finally, the updated skb hooks, attached below.
    > 
    > Note that the 'security' field in the skb header is no longer in use by
    > the main kernel, and one of the networking maintainers has indicated that
    > we may be able to claim it's namespace for 2.6.
    
    with just alloc, free, copy and clone, i don't fully understand how you
    aniticipate using the sk_buff security label.  e.g. one of the problems
    i had was the device info is not necessarily accurate in higher level tcp
    functions, and if i had my way i would have labelled the device the
    packet arrived on.  how would you do this?
    
    -chris
    
    _______________________________________________
    linux-security-module mailing list
    linux-security-moduleat_private
    http://mail.wirex.com/mailman/listinfo/linux-security-module
    



    This archive was generated by hypermail 2b30 : Wed Jul 25 2001 - 18:03:25 PDT