Re: [PATCH 14/15] NFSD: Server implementation of MAC Labeling

[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]

 



On Sat, Feb 16, 2013 at 03:44:59PM -0500, Steve Dickson wrote:
> On 12/02/13 17:54, J. Bruce Fields wrote:
> > 
> > Although: don't we need to check whether the exported filesystem
> > supports security labels?
> I took a quick look around and didn't see any interface to do that.
> Is it even possible to do this?

Try fetching a security label and check whether the response is
EOPNOTSUPP, I think.  That's what the ACL code does.

> >> +	/* XXX: should we have a MAY_SSECCTX? */
> > 
> > I don't know, should we?
> I vote no! ;-) What is that? 

Maybe this is a question for Dave--who wrote that comment?  How should
we be checking for permissions to set the security label?

--b.
--
To unsubscribe from this list: send the line "unsubscribe linux-nfs" in
the body of a message to majordomo@xxxxxxxxxxxxxxx
More majordomo info at  http://vger.kernel.org/majordomo-info.html


[Index of Archives]     [Linux Filesystem Development]     [Linux USB Development]     [Linux Media Development]     [Video for Linux]     [Linux NILFS]     [Linux Audio Users]     [Yosemite Info]     [Linux SCSI]

  Powered by Linux