Re: [PATCH RFC] file capabilities: clear fcaps on inode change

2007-07-30 Thread Stephen Smalley
On Sun, 2007-07-29 at 08:48 -0700, Casey Schaufler wrote: --- Serge E. Hallyn [EMAIL PROTECTED] wrote: Quoting Andrew Morgan ([EMAIL PROTECTED]): -BEGIN PGP SIGNED MESSAGE- Hash: SHA1 Is this the sort of change that should be abstracted into the security module API?

Re: [xfs-masters] [RFC: 2.6 patch] make the *FS_SECURITY options no longer user visible

2007-07-30 Thread Stephen Smalley
On Mon, 2007-07-30 at 09:29 +1000, David Chinner wrote: On Sun, Jul 29, 2007 at 05:02:09PM +0200, Adrian Bunk wrote: Please correct me if any of the following assumptions is wrong: - SELinux is currently the only user of filesystem security labels shipped with the Linux kernel - if a

Re: [RFC: 2.6 patch] make the *FS_SECURITY options no longer user visible

2007-07-30 Thread Serge E. Hallyn
Quoting Adrian Bunk ([EMAIL PROTECTED]): Please correct me if any of the following assumptions is wrong: - SELinux is currently the only user of filesystem security labels shipped with the Linux kernel - if a user has SELinux enabled he wants his filesystems to support security labels

Re: [RFC][PATCH] Simplified mandatory access control kernel implementation

2007-07-30 Thread Casey Schaufler
--- Joshua Brindle [EMAIL PROTECTED] wrote: ... On the guard implementation I'd like to note that assured pipelines are pretty hard to get right. Without object class and create granularity (at the very least) you might find it very difficult to control backflow. Consider that 1) many