Re: [RFC PATCH v2 00/13] SELinux support for Infiniband RDMA

[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]

 



On Thu, Apr 07, 2016 at 02:33:45AM +0300, Dan Jurgens wrote:

> Currently there is no way to provide granular access control to an Infiniband
> fabric.  By providing an ability to restrict user access to specific virtual
> subfabrics administrators can limit access to bandwidth and isolate users on
> the fabric.

Do you actually have a concrete use case for this?

This seems superficially similar to netlabel, which I guess targets a
certain niche, but I'm really wondering with all the other container
patches if this was supposed to be done with namespaces...

> An Infiniband device (ibdev) is labeled by name and port number.  There is a
> single access vector for ibdevs as well, called "smi".

This is called an End Port (SMI is something else in the IB
spec). Please use the standard terminology.

Jason
--
To unsubscribe from this list: send the line "unsubscribe linux-rdma" in
the body of a message to majordomo@xxxxxxxxxxxxxxx
More majordomo info at  http://vger.kernel.org/majordomo-info.html



[Index of Archives]     [Linux USB Devel]     [Video for Linux]     [Linux Audio Users]     [Photo]     [Yosemite News]     [Yosemite Photos]     [Linux Kernel]     [Linux SCSI]     [XFree86]
  Powered by Linux