Re: [PATCH v5 6/7] selinux: Revalidate invalid inode security labels

[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]

 



On Mon, Nov 2, 2015 at 8:27 PM, Paul Moore <paul@xxxxxxxxxxxxxx> wrote:
> On Sunday, November 01, 2015 06:24:32 PM Andreas Gruenbacher wrote:
>> When fetching an inode's security label, check if it is still valid, and
>> try reloading it if it is not. Reloading will fail when we are in RCU
>> context which doesn't allow sleeping, or when we can't find a dentry for
>> the inode.  (Reloading happens via iop->getxattr which takes a dentry
>> parameter.)  When reloading fails, continue using the old, invalid
>> label.
>>
>> Signed-off-by: Andreas Gruenbacher <agruenba@xxxxxxxxxx>
>> Acked-by: Stephen Smalley <sds@xxxxxxxxxxxxx>
>
> Generally I would say that you made enough changes between v4 and v5 that
> Stephen's ACK should have been dropped,

Sorry, my mistake.

> but considering that he suggested the changes I think's it's okay to leave it as-is.
>
> Stephen, I'm reviewing/merging these changes now for the selinux#next-queue,
> speak up if you have want your ACK removed.

Thanks,
Andreas
_______________________________________________
Selinux mailing list
Selinux@xxxxxxxxxxxxx
To unsubscribe, send email to Selinux-leave@xxxxxxxxxxxxx.
To get help, send an email containing "help" to Selinux-request@xxxxxxxxxxxxx.



[Index of Archives]     [Selinux Refpolicy]     [Linux SGX]     [Fedora Users]     [Fedora Desktop]     [Yosemite Photos]     [Yosemite Camping]     [Yosemite Campsites]     [KDE Users]     [Gnome Users]

  Powered by Linux