All of lore.kernel.org
 help / color / mirror / Atom feed
From: Klaus Weidner <klaus@atsec.com>
To: "Christopher J. PeBenito" <cpebenito@tresys.com>
Cc: selinux@tycho.nsa.gov
Subject: Re: [PATCH RFC 1/2] stricter MLS policy constraints
Date: Mon, 8 Jan 2007 22:43:25 -0600	[thread overview]
Message-ID: <20070109044325.GA24321@w-m-p.com> (raw)
In-Reply-To: <1168271261.12883.4.camel@sgc.columbia.tresys.com>

On Mon, Jan 08, 2007 at 10:47:41AM -0500, Christopher J. PeBenito wrote:
> On Tue, 2006-12-12 at 01:34 -0600, Klaus Weidner wrote: 
> > Rename the "mlsfilewriteinrange" attribute with no functional changes.
> > The reason for the renaming is that this is an object attribute (like
> > "mlstrustedobject"), and it's confusing to use the naming scheme usually
> > used for subject attributes for it. It's currently only used for the
> > printer device object.
> > 
> > See 0/2 message for additional explanations.
> 
> Sorry for the late response, but its taken some time to clear out the
> backlog while I was out of the office.  This patch cannot be applied
> upstream because there is no compatibility for renaming the attribute.
> Since modules are statically compiled, anything that happens to use this
> attribute will fail to link.  The other patches seemed ok.
> 
> > -attribute mlsfilewriteinrange;
> > +attribute mlsrangedobject;

Is this really a big problem? If I remember correctly the attribute had
been introduced specifically to support the ranged printer device type
needed for Matt's labeled Cups extensions, and it's only used in a single
place in the shipped policy (which the patch updated). 

Of course I don't want to cause trouble for people using the refpolicy
with out-of-tree modules, is there a way to do the rename using an alias
interface or deprecation warning to give people time to switch? I think
it would be bad to be stuck with historically grown interfaces forever,
especially if the feature was just added recently.

-Klaus

--
This message was distributed to subscribers of the selinux mailing list.
If you no longer wish to subscribe, send mail to majordomo@tycho.nsa.gov with
the words "unsubscribe selinux" without quotes as the message.

  reply	other threads:[~2007-01-09  4:46 UTC|newest]

Thread overview: 12+ messages / expand[flat|nested]  mbox.gz  Atom feed  top
2006-12-12  7:28 [PATCH RFC 0/2] stricter MLS policy constraints Klaus Weidner
2006-12-12  7:34 ` [PATCH RFC 1/2] " Klaus Weidner
2007-01-08 15:47   ` Christopher J. PeBenito
2007-01-09  4:43     ` Klaus Weidner [this message]
2006-12-12  7:38 ` [PATCH RFC 0/2] " Klaus Weidner
2006-12-12  7:40 ` [PATCH RFC 2/2] " Klaus Weidner
2006-12-12 15:26 ` [PATCH RFC 3/2] " Klaus Weidner
2006-12-13 20:50 ` [PATCH RFC 0/2] " Paul Moore
2006-12-13 21:40   ` Klaus Weidner
2006-12-13 21:50     ` Paul Moore
2006-12-14 15:48       ` Joy Latten
2007-01-08 16:02       ` Christopher J. PeBenito

Reply instructions:

You may reply publicly to this message via plain-text email
using any one of the following methods:

* Save the following mbox file, import it into your mail client,
  and reply-to-all from there: mbox

  Avoid top-posting and favor interleaved quoting:
  https://en.wikipedia.org/wiki/Posting_style#Interleaved_style

* Reply using the --to, --cc, and --in-reply-to
  switches of git-send-email(1):

  git send-email \
    --in-reply-to=20070109044325.GA24321@w-m-p.com \
    --to=klaus@atsec.com \
    --cc=cpebenito@tresys.com \
    --cc=selinux@tycho.nsa.gov \
    /path/to/YOUR_REPLY

  https://kernel.org/pub/software/scm/git/docs/git-send-email.html

* If your mail client supports setting the In-Reply-To header
  via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line before the message body.
This is an external index of several public inboxes,
see mirroring instructions on how to clone and mirror
all data and code used by this external index.