From: "Serge E. Hallyn" <serue-r/Jw6+rmf7HQT0dZR+AlfA@public.gmane.org>
To: Linux Containers <containers-qjLDD68F18O7TbgM5vRIOg@public.gmane.org>
Subject: Re: [PATCH 1/1] cr: lsm: actually cache entries
Date: Thu, 8 Oct 2009 16:41:11 -0500 [thread overview]
Message-ID: <20091008214111.GA7588@us.ibm.com> (raw)
In-Reply-To: <20091008194720.GA648-r/Jw6+rmf7HQT0dZR+AlfA@public.gmane.org>
Quoting Serge E. Hallyn (serue-r/Jw6+rmf7HQT0dZR+AlfA@public.gmane.org):
> Somewhere along the way, the lsm c/r patchset seems to have
> dropped the code caching whether a particular void*security
> had already been checkpointed. Note that checkpoint a
> void* security means allocing a struct containing the secref
> and the string representation of the context. That leaves us
> with no way to tell, given only the void*security, whether
> that context has been checkpointed before (as part of checkpointing
> a different object of the same object type and security context).
>
> This patch re-introduces a moronic unsorted per-checkpoint list
> of checkpointed contexts, used only at checkpoint time, so that
> we can re-use secrefs. Converting this to an rblist or hash will
> be trivial, but isn't done here to try and make clear why we
> actually need this.
>
> (applies on top of existing LSM c/r patches at
> git://git.kernel.org/pub/scm/linux/kernel/git/sergeh/linux-cr.git)
>
> Signed-off-by: Serge E. Hallyn <serue-r/Jw6+rmf7HQT0dZR+AlfA@public.gmane.org>
Matt called me on this over irc, and as a result I think I've
found a trivial way to do this much better... pls ignore for
now.
thanks,
-serge
prev parent reply other threads:[~2009-10-08 21:41 UTC|newest]
Thread overview: 2+ messages / expand[flat|nested] mbox.gz Atom feed top
2009-10-08 19:47 [PATCH 1/1] cr: lsm: actually cache entries Serge E. Hallyn
[not found] ` <20091008194720.GA648-r/Jw6+rmf7HQT0dZR+AlfA@public.gmane.org>
2009-10-08 21:41 ` Serge E. Hallyn [this message]
Reply instructions:
You may reply publicly to this message via plain-text email
using any one of the following methods:
* Save the following mbox file, import it into your mail client,
and reply-to-all from there: mbox
Avoid top-posting and favor interleaved quoting:
https://en.wikipedia.org/wiki/Posting_style#Interleaved_style
* Reply using the --to, --cc, and --in-reply-to
switches of git-send-email(1):
git send-email \
--in-reply-to=20091008214111.GA7588@us.ibm.com \
--to=serue-r/jw6+rmf7hqt0dzr+alfa@public.gmane.org \
--cc=containers-qjLDD68F18O7TbgM5vRIOg@public.gmane.org \
/path/to/YOUR_REPLY
https://kernel.org/pub/software/scm/git/docs/git-send-email.html
* If your mail client supports setting the In-Reply-To header
via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line
before the message body.
This is an external index of several public inboxes,
see mirroring instructions on how to clone and mirror
all data and code used by this external index.