Re: [PATCH 14/15] NFSD: Server implementation of MAC Labeling

[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]

 



On Sat, Feb 16, 2013 at 03:44:59PM -0500, Steve Dickson wrote:
> On 12/02/13 17:54, J. Bruce Fields wrote:
> > 
> > Although: don't we need to check whether the exported filesystem
> > supports security labels?
> I took a quick look around and didn't see any interface to do that.
> Is it even possible to do this?

Try fetching a security label and check whether the response is
EOPNOTSUPP, I think.  That's what the ACL code does.

> >> +	/* XXX: should we have a MAY_SSECCTX? */
> > 
> > I don't know, should we?
> I vote no! ;-) What is that? 

Maybe this is a question for Dave--who wrote that comment?  How should
we be checking for permissions to set the security label?

--b.
--
To unsubscribe from this list: send the line "unsubscribe linux-fsdevel" in
the body of a message to majordomo@xxxxxxxxxxxxxxx
More majordomo info at  http://vger.kernel.org/majordomo-info.html


[Index of Archives]     [Linux Ext4 Filesystem]     [Union Filesystem]     [Filesystem Testing]     [Ceph Users]     [Ecryptfs]     [AutoFS]     [Kernel Newbies]     [Share Photos]     [Security]     [Netfilter]     [Bugtraq]     [Yosemite News]     [MIPS Linux]     [ARM Linux]     [Linux Security]     [Linux Cachefs]     [Reiser Filesystem]     [Linux RAID]     [Samba]     [Device Mapper]     [CEPH Development]
  Powered by Linux