On Tue, 17 Nov 2015, Seth Forshee wrote:

> Security labels from unprivileged mounts in user namespaces must
> be ignored. Force superblocks from user namespaces whose labeling
> behavior is to use xattrs to use mountpoint labeling instead.
> For the mountpoint label, default to converting the current task
> context into a form suitable for file objects, but also allow the
> policy writer to specify a different label through policy
> transition rules.
> 
> Pieced together from code snippets provided by Stephen Smalley.
> 
> Signed-off-by: Seth Forshee <seth.fors...@canonical.com>
> Acked-by: Stephen Smalley <s...@tycho.nsa.gov>


Acked-by: James Morris <james.l.mor...@oracle.com>

-- 
James Morris
<jmor...@namei.org>

--
To unsubscribe from this list: send the line "unsubscribe 
linux-security-module" in
the body of a message to majord...@vger.kernel.org
More majordomo info at  http://vger.kernel.org/majordomo-info.html

Reply via email to