[<prev] [next>] [<thread-prev] [thread-next>] [day] [month] [year] [list]
Message-Id: <200804081701.48667.paul.moore@hp.com>
Date: Tue, 8 Apr 2008 17:01:48 -0400
From: Paul Moore <paul.moore@...com>
To: hadi@...erus.ca
Cc: linux-security-module@...r.kernel.org, netdev@...r.kernel.org,
selinux@...ho.nsa.gov
Subject: Re: [RFC PATCH 2/2] LSM: Make the Labeled IPsec hooks more stack friendly
On Tuesday 08 April 2008 6:24:52 am jamal wrote:
> On Mon, 2008-07-04 at 19:16 -0400, Paul Moore wrote:
> > The xfrm_get_policy() and xfrm_add_pol_expire() put some rather
> > large structs on the stack to work around the LSM API.
>
> You missed a spot which applies similar logic:
> net/key/af_key.c::pfkey_spddelete()
Thanks, I'll check all the pfkey bits to see if anything else jumps out
too ... and figure out why my config wasn't building pfkey :)
--
paul moore
linux @ hp
--
To unsubscribe from this list: send the line "unsubscribe netdev" in
the body of a message to majordomo@...r.kernel.org
More majordomo info at http://vger.kernel.org/majordomo-info.html
Powered by blists - more mailing lists