On Fri, Aug 26, 2005 at 02:00:56PM -0400, Stephen Smalley wrote: > > That makes capability part of the core kernel again, just like DAC, > which means that you can never override a capability denial in your > module. We sometimes want to override the capability implementation, > not just apply further restrictions after it. cap_inode_setxattr and > cap_inode_removexattr are examples; they prohibit any access to _all_ Right, the rationale behind cap_stack.c. Good point. I'd forgotten that. I guess selective internal composition is the way to go. Tony
This archive was generated by hypermail 2.1.3 : Fri Aug 26 2005 - 11:16:02 PDT