On Friday, January 10, 2014 09:42:42 AM Stephen Smalley wrote: > On 01/09/2014 06:07 PM, Eric Paris wrote: > > I believe we need a new initial sid. SECINITSID_INVALID_LABEL.... > > Difficult (impossible?) to do in a fully backward compatible manner (to > include the case of loading new policy on old kernel, whether initially > or update/reload on an already running kernel with an older policy). Do we really need to worry about being able to load new policy into a old kernel? In general I thought the backward compatible issue was that newer kernels needed to support older userspace, not the other way around. -- paul moore www.paul-moore.com _______________________________________________ Selinux mailing list Selinux@xxxxxxxxxxxxx To unsubscribe, send email to Selinux-leave@xxxxxxxxxxxxx. To get help, send an email containing "help" to Selinux-request@xxxxxxxxxxxxx.