On Tue, 5 Apr 2016, Daniel Jurgens wrote:

> On 4/4/2016 8:13 PM, James Morris wrote:
> > On Tue, 5 Apr 2016, Dan Jurgens wrote:
> > 
> >> From: Daniel Jurgens <[email protected]>
> >>
> >> Currently there is no way to provide granular access control to an 
> >> Infiniband
> >> fabric.  By providing an ability to restrict user access to specific 
> >> virtual
> >> subfabrics administrators can limit access to bandwidth and isolate users 
> >> on
> >> the fabric.
> > 
> > Where are the LSM hooks placed?
> > 
> > 
> > 
> The LSM hooks are defined in patch 1/7 of this series.  There are 4 that
> will be called from ib_core, and one that's implemented by ib_core to be
> called by a security module if the policy or enforcement setting change
> (infiniband_flush).  That call from SELinux is added in patch 3/7 of
> this series.

Can you post the ib_core patches, too?


-- 
James Morris
<[email protected]>

_______________________________________________
Selinux mailing list
[email protected]
To unsubscribe, send email to [email protected].
To get help, send an email containing "help" to [email protected].

Reply via email to