On Thu, 24 Jan 2008, Stephen Smalley wrote: > > BTW, given that it entails a non-trivial amount of work, it would be > good to roll in any other desired permission additions at the same time > if possible. For example, we've also talked about adding a 'map' check > on mmap and mprotect so that we can distinguish memory mapped access > (since it has different implications for revocation). Added these to http://selinuxproject.org/page/Kernel_Development Please update that todo list if something like this is discussed & seem a candidate for being done at some point (or email someone with an account). -- James Morris <jmorris@xxxxxxxxx> -- This message was distributed to subscribers of the selinux mailing list. If you no longer wish to subscribe, send mail to majordomo@xxxxxxxxxxxxx with the words "unsubscribe selinux" without quotes as the message.