LSM adapted to support XFS (fwd)

From: Oliver Tennert (tennert@science-computing.de)
Date: Wed Dec 11 2002 - 01:20:33 PST

  • Next message: Listar: "Listar command results: No commands found"

    Hi,
    
    maybe I am not a good kernel patcher. Nevertheless I have tried to combine
    LSM patches with an XFS-supporting kernel, which has some further
    unrelated enhancements like lm-sensors, acpi and so on, as well as Trond
    Myklebust's NFS client patches.
    
    The adaption turned out to be fairly easy: I had to change some lines in
    some fs-related files, and the file
    security/selinux/hooks.c, mainly due to the change in the quota code for
    XFS kernels. Furthermore, a non-matching include statement in
    security/lids/lids_net.c had to be left out.
    
    So far so good. The kernel itself is running as stable as the "original"
    non-LSM kernel. Though I have not yet loaded an SELinux policy I am quite
    optimistic it would work. Unfortunately, running the NFS server leads
    perpetual kernel oopsing. I am aware of the fact that there have been
    posted some patches addressing this problem some weeks ago, and I have
    found these are NOT included in Russell's current kernel patches dating
    9 December at "http://www.coker.com.au/selinux/kern/".
    However, an earlier attempt with a 2.4.19
    kernel DEFINITELY INCLUDING the relevant patches had led to the same
    results:
    
    Anyway the problem still
    remains, but I am unsure whether this is due to the exported filesystems
    being XFS filesystems -- I have not checked with Ext2/3 filesystems yet.
    
    I realize that in vanilla 2.4.20 extended
    attributes have found their way into the kernel, but are not yet handled
    by the LSM infrastructure in the current 2.4 line, right?
    
    I have included my "adapted" patch based on Russell's patch, which you may
    possibly find pretty ill-done. But I am interested in having an
    XFS-capable kernel with LSM, and would gladly try to help getting it.
    
    Many thanks in advance for your help.
    
    Best regards
    
    Oliver Tennert
    
    		   Dr. Oliver Tennert
                        
      		   +49 -7071 -9457-598
                              
     		   e-mail: O.Tennert@science-computing.de
      		   science + computing AG
      		   Hagellocher Weg 71                  
       		   D-72070 Tuebingen                  
                                         
    
    
    
    

    _______________________________________________ linux-security-module mailing list linux-security-moduleat_private http://mail.wirex.com/mailman/listinfo/linux-security-module



    This archive was generated by hypermail 2b30 : Wed Dec 11 2002 - 01:29:39 PST