On Mon, 16 Aug 2004, Serge Hallyn wrote: > Attached is a proposed patch to allow LSM's to hide the existance of > network interfaces. This appears to require more than one pair of > hooks. The netdev_* hooks are generic network device hooks. The inet_* > hooks are for internet devices. The latter know about device aliases, > such as eth0:0. What security purpose does it serve to hide the existence of a network interface? I don't think this patch has much chance of upstream acceptance. Can BSD jail work without these hooks? - James -- James Morris <jmorris@private>
This archive was generated by hypermail 2.1.3 : Mon Aug 16 2004 - 11:56:35 PDT