On Friday, November 07, 2014 10:10:34 PM David Howells wrote: > Paul Moore <paul@xxxxxxxxxxxxxx> wrote: > > This didn't occur to me earlier, but we may want to pick a different > > phrase to use instead of "copy_up" as that has a special meaning for some > > security/MLS folks... > > It does? Yep, think upgrading the sensitivity level, e.g. relabeling a "secret" file up to a "top secret". > security_inode_make_union()? Actually, after thinking on this some more, forget I mentioned anything. The existing "copy_up" makes the most sense for the LSM hook (it matches the naming of the caller in overlayfs, which is a nice thing) and the number of times any MLS will look that closely at the kernel code is going to be very few. -- paul moore www.paul-moore.com _______________________________________________ Selinux mailing list Selinux@xxxxxxxxxxxxx To unsubscribe, send email to Selinux-leave@xxxxxxxxxxxxx. To get help, send an email containing "help" to Selinux-request@xxxxxxxxxxxxx.