On Fri, 9 May 2008, Stephen Smalley wrote: > Simplify and improve the robustness of the SELinux ioctl checking by > using the "access mode" bits of the ioctl command to determine the > permission check rather than dealing with individual command values. > This removes any knowledge of specific ioctl commands from SELinux > and follows the same guidance we gave to Smack earlier. Looks good to me, let me know if you want it applied to for-akpm. -- James Morris <jmorris@xxxxxxxxx> -- This message was distributed to subscribers of the selinux mailing list. If you no longer wish to subscribe, send mail to majordomo@xxxxxxxxxxxxx with the words "unsubscribe selinux" without quotes as the message.