Re: nfsservctl hook in 2.5

From: Chris Wright (chrisat_private)
Date: Fri Apr 12 2002 - 10:18:02 PDT

  • Next message: Red Phoenix: "Snare version 0.9 released"

    * Stephen Smalley (sdsat_private) wrote:
    > On Thu, 11 Apr 2002, Chris Wright wrote:
    > > 3) This is a filesystem, remove the nfsservctl hook since we have the
    > > standard filesystem hooks.  This conceptually preserves our current stance
    > > which tries to avoid placing filesystem specific hooks.  And reading
    > > the data passed in the buffers during a file write seems a bit strange.
    > > Labelling via standard post_lookup is a little tough, since currently
    > > this is an in kernel fs and it manually populates the dcache.
    > 
    > This option appears to be the most consistent with LSM, as you noted.  The
    > first option would just be a short term solution, encouraging module
    > writers to rely on support that will soon vanish.  The second option is
    > too invasive, as you also noted.
    
    Sounds good, I'll remove it.  And with that I can get a 2.5.7 snapshot
    released ;-)
    
    thanks,
    -chris
    _______________________________________________
    linux-security-module mailing list
    linux-security-moduleat_private
    http://mail.wirex.com/mailman/listinfo/linux-security-module
    



    This archive was generated by hypermail 2b30 : Fri Apr 12 2002 - 10:19:42 PDT