On Tue, Jul 02, 2002 at 05:18:40PM -0400, Valdis.Kletnieksat_private wrote: > This raises a second concern - who's job is it to watch the kernel and > make sure that new hooks are added in functionality when needed? General kernel etiquette (sp?) is that whoever makes an important change in one location is in charge of making corresponding changes in other code that depended upon the old behavior. However, when, say, Al Viro makes a VFS change, he can hardly be expected to make corresponding changes to the 20+ filesystems. I think LSM's complexity is nowhere near this bad, so hopefully, those who make changes will be able to propogate appropriate changes through LSM when needed. And yes, it will require vigilence on the part of module authors. (Who better understands the security implications of code changes? :) -- http://www.wirex.com/
This archive was generated by hypermail 2b30 : Tue Jul 02 2002 - 14:57:38 PDT