Re: [RFC] [Stacking v4 2/3] New version of SELinux patch to support stacking

From: Stephen Smalley (sds@private)
Date: Tue Dec 07 2004 - 05:10:54 PST


On Mon, 2004-12-06 at 18:02, Serge Hallyn wrote:
> Hmm, in order to know about the performance, I suppose stacker will need
> to be tested with a version of SELinux patched to not call
> dummy_security_ops as a secondary.  Hopefully that will provide more
> comparable results than the last run...

Yes, and I'd also suggest changing all calls to the top-level capable()
function within SELinux, capabilities, and dummy to instead only call
their own foo_capable() functions.  Otherwise, you are likely getting
duplicate processing by each module when using stacker.

-- 
Stephen Smalley <sds@private>
National Security Agency



This archive was generated by hypermail 2.1.3 : Tue Dec 07 2004 - 05:16:20 PST