On 4/4/2016 8:13 PM, James Morris wrote:
> On Tue, 5 Apr 2016, Dan Jurgens wrote:
> 
>> From: Daniel Jurgens <[email protected]>
>>
>> Currently there is no way to provide granular access control to an Infiniband
>> fabric.  By providing an ability to restrict user access to specific virtual
>> subfabrics administrators can limit access to bandwidth and isolate users on
>> the fabric.
> 
> Where are the LSM hooks placed?
> 
> 
> 
The LSM hooks are defined in patch 1/7 of this series.  There are 4 that
will be called from ib_core, and one that's implemented by ib_core to be
called by a security module if the policy or enforcement setting change
(infiniband_flush).  That call from SELinux is added in patch 3/7 of
this series.

_______________________________________________
Selinux mailing list
[email protected]
To unsubscribe, send email to [email protected].
To get help, send an email containing "help" to [email protected].

Reply via email to