Re: [RFC] [Stacking v4 2/3] New version of SELinux patch to support stacking

From: Stephen Smalley (sds@private)
Date: Fri Dec 17 2004 - 12:20:02 PST


On Fri, 2004-12-17 at 16:00, Serge Hallyn wrote:
> Is that the behavior we want to preserve?  Or do we want to go ahead and
> use capable(CAP_SYS_ADMIN) in the dummy version?

IMHO, having vm_enough_memory trigger setting of the PF_SUPERPRIV flag
is a mistake.  dummy and capability should only be calling their own
private capable functions, not the top-level one.

-- 
Stephen Smalley <sds@private>
National Security Agency



This archive was generated by hypermail 2.1.3 : Fri Dec 17 2004 - 12:28:59 PST