Re: [RFC] Add vfsmount to vfs helper functions.

2008-02-02 Thread Tetsuo Handa
Hello. Al Viro wrote: On Fri, Jan 25, 2008 at 07:20:56PM +0900, Kentaro Takeda wrote: In the LSM ml, we are discussing about how to know requested pathnames within LSM modules. Currently, VFS helper functions don't pass struct vfsmount parameter. Therefore, we cannot calculate

Re: [PATCH] per-process securebits

2008-02-02 Thread Andrew G. Morgan
-BEGIN PGP SIGNED MESSAGE- Hash: SHA1 Andrew Morton wrote: | On Fri, 01 Feb 2008 00:11:37 -0800 Andrew G. Morgan [EMAIL PROTECTED] wrote: | | [This patch represents a no-op unless CONFIG_SECURITY_FILE_CAPABILITIES | is enabled at configure time.] | | Patches like this scare the pants

Re: [PATCH] per-process securebits

2008-02-02 Thread Andrew G. Morgan
-BEGIN PGP SIGNED MESSAGE- Hash: SHA1 [EMAIL PROTECTED] wrote: | Quoting Andrew G. Morgan ([EMAIL PROTECTED]): | -BEGIN PGP SIGNED MESSAGE- | Hash: SHA1 | | Here is the patch to add per-process securebits. | | Its all code that lives inside the capability LSM and the new

Re: [PATCH] per-process securebits

2008-02-02 Thread Ismail Dönmez
At Sunday 03 February 2008 around 08:18:12 Andrew Morton wrote: So how do we ever get to the stage where we can recommend that distributors turn these things on, and have them agree with us? FWIW with my distributor hat on I think File system capabilities are very nice and enables one to ship