On Tue, 4 Feb 2003, Stephen D. Smalley wrote: > Hasn't skb->dev been cleared before we reach the sk_filter call? We can't > infer a security label for the packet without knowing the receiving device. As mentioned off-list, I'm going to try moving the sk_filter() call so that we get called before skb->dev has been cleared. A snapshot of the network patchset is online at: http://www.intercode.com.au/jmorris/patches/lsm/ Just waiting for some feedback from the maintainers on this. - James -- James Morris <jmorrisat_private> _______________________________________________ linux-security-module mailing list linux-security-moduleat_private http://mail.wirex.com/mailman/listinfo/linux-security-module
This archive was generated by hypermail 2b30 : Wed Feb 05 2003 - 05:26:14 PST