On Fri, Sep 14, 2012 at 11:32 AM, Stephen Smalley <sds@xxxxxxxxxxxxx> wrote:
On Fri, 2012-09-14 at 11:24 -0700, William Roberts wrote:Possibly, but I don't see any DAC checks or capable calls in the current
> Based on this article and "sharing
> buffers", http://lwn.net/Articles/480055/
>
>
> We may need to instrument LSM hooks for ION.
>
>
> Thoughts?
ion driver code. If the only way to share is by passing open fds, then
we already control that via the existing SELinux hooks.
--
Stephen Smalley
National Security Agency
Respectfully,
William C Roberts