Re: [PATCH 2/5] Rework stubs in security.h

From: Tony Jones (tonyj@private)
Date: Fri Aug 26 2005 - 11:11:30 PDT


On Fri, Aug 26, 2005 at 02:00:56PM -0400, Stephen Smalley wrote:
> 
> That makes capability part of the core kernel again, just like DAC,
> which means that you can never override a capability denial in your
> module.  We sometimes want to override the capability implementation,
> not just apply further restrictions after it.  cap_inode_setxattr and
> cap_inode_removexattr are examples; they prohibit any access to _all_

Right, the rationale behind cap_stack.c.  Good point.  I'd forgotten that.

I guess selective internal composition is the way to go.

Tony



This archive was generated by hypermail 2.1.3 : Fri Aug 26 2005 - 11:16:02 PDT