[<prev] [next>] [<thread-prev] [thread-next>] [day] [month] [year] [list]
Message-ID: <Line.LNX.4.64.0703222056080.25271@d.namei>
Date: Thu, 22 Mar 2007 20:56:50 -0400 (EDT)
From: James Morris <jmorris@...ei.org>
To: Joy Latten <latten@...tin.ibm.com>
cc: David Miller <davem@...emloft.net>, selinux@...ho.nsa.gov,
netdev@...r.kernel.org, vyekkirala@...stedcs.com
Subject: Re: [PATCH]: Add security check before flushing SAD/SPD
On Thu, 22 Mar 2007, Joy Latten wrote:
> > Perhaps a better semantic would be to fail the entire flush operation if
> > one of the security checks failed. e.g. loop through for permissions
> > first, then if all ok, loop through for deletion.
> >
> Ok, will code this up and test it if there are no objections.
I'd suggest making the permission loop a noop if CONFIG_SECURITY=n, via a
static inline function.
--
James Morris
<jmorris@...ei.org>
-
To unsubscribe from this list: send the line "unsubscribe netdev" in
the body of a message to majordomo@...r.kernel.org
More majordomo info at http://vger.kernel.org/majordomo-info.html
Powered by blists - more mailing lists