Re: [RFC PATCH] selinux: introduce and use ad_init_net*() helpers

[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]

 



On Wed, Jul 19, 2023 at 5:36 AM Paolo Abeni <pabeni@xxxxxxxxxx> wrote:
> On Tue, 2023-07-18 at 09:17 +0200, Ondrej Mosnacek wrote:

...

> > Since there is nothing SELinux-specific in these helpers, maybe it
> > would be better to move them into <linux/lsm_audit.h> and also convert
> > the other users of lsm_network_audit (Smack and AppArmor) to use them.
> > (In fact AppArmor already seems to do something similar using its own
> > macros.)

...

> TL;DR: I would avoid extending the helpers usage at this point. If
> there is interest from other other lsm's maintainers, I think such
> extension could be a follow-up.

I agree.  Quite frankly there is a lot of stuff in the LSM common
audit code that could be improved.

-- 
paul-moore.com




[Index of Archives]     [Selinux Refpolicy]     [Linux SGX]     [Fedora Users]     [Fedora Desktop]     [Yosemite Photos]     [Yosemite Camping]     [Yosemite Campsites]     [KDE Users]     [Gnome Users]

  Powered by Linux