All of lore.kernel.org
 help / color / mirror / Atom feed
* Re: SELinux and non-ext[23] file systems
@ 2001-11-19 16:15 Harald von Fellenberg - Sun Switzerland Zurich - Technology Strategy Office
  2001-11-19 16:37 ` Stephen Smalley
  2001-11-22 10:36 ` Hans Reiser
  0 siblings, 2 replies; 7+ messages in thread
From: Harald von Fellenberg - Sun Switzerland Zurich - Technology Strategy Office @ 2001-11-19 16:15 UTC (permalink / raw)
  To: Harald.Von-Fellenberg, sds; +Cc: selinux

IT WORKS ON REISERFS!!!

Why did you not tell me before ... :-)
I will now invest my brain cycles on making the utils compile under Suse 7.x

Thanks and regards

Harald
PS here my patch :-)

--- setfiles/Makefile.orig      Wed Jul 18 22:38:11 2001
+++ setfiles/Makefile   Mon Nov 19 16:19:18 2001
@@ -9,6 +9,7 @@
 
 relabel:  $(FILECONTEXTS) setfiles
        ./setfiles $(FILECONTEXTS) `mount | awk '/ext2/{print $$3}'`
+       ./setfiles $(FILECONTEXTS) `mount | awk '/reiserfs/{print $$3}'`
        touch relabel
 
 install:  relabel

>
>On Mon, 19 Nov 2001, Harald von Fellenberg - Sun Switzerland Zurich - 
Technology Strategy Office wrote:
>
>> This said, I would like to re-raise the importance of non-ext2 file system
>> support, notably ReiserFS. It has been pointed out before, by Stephen 
Smalley,
>> that this should in principle be easy to integrate (the per-node sec context
>> needs to be stored in a file rather than in an unused field of the on-disk 
inode
>> structure). However, I am not aware of anyone tackling this implementation.
>
>Only the original SELinux prototype was limited to the ext2 filesystem,
>due to the use of a spare field in the on-disk ext2 inode to store the
>persistent security identifier (PSID).  When we transitioned to LSM, we
>extended the persistent label mapping to maintain the inode-to-PSID
>mapping as a regular file because LSM does not provide filesystem-specific
>hooks.  Hence, the LSM-based SELinux prototype should be able to use
>ReiserFS, although we haven't tried it.
>
>--
>Stephen D. Smalley, NAI Labs
>ssmalley@nai.com
>
>
>
>
>
>--
>You have received this message because you are subscribed to the selinux list.
>If you no longer wish to subscribe, send mail to majordomo@tycho.nsa.gov with
>the words "unsubscribe selinux" without quotes as the message.

**********************************************************
 Dr. Harald von Fellenberg  
 Chief Technologist        Global Sales Organisation
 Tel:    +41 1 908 9230    Sun Microsystems (Schweiz) AG
 Fax:    +41 1 908 9001    Javastr. 2 
 Mobile: +41 79 349 0393   CH-8604 Volketswil
 mailto:harald.von-fellenberg@sun.com
**********************************************************


--
You have received this message because you are subscribed to the selinux list.
If you no longer wish to subscribe, send mail to majordomo@tycho.nsa.gov with
the words "unsubscribe selinux" without quotes as the message.

^ permalink raw reply	[flat|nested] 7+ messages in thread
* SELinux and non-ext[23] file systems
@ 2001-11-19 14:51 Harald von Fellenberg - Sun Switzerland Zurich - Technology Strategy Office
  2001-11-19 14:57 ` Stephen Smalley
  0 siblings, 1 reply; 7+ messages in thread
From: Harald von Fellenberg - Sun Switzerland Zurich - Technology Strategy Office @ 2001-11-19 14:51 UTC (permalink / raw)
  To: sds; +Cc: selinux, Harald.Von-Fellenberg

First the good news. Last week I gave a presentation about secure operating 
systems, running the slides on Staroffice 6.0 beta on SELinux 20011016. It ran 
smoothly like a humming bee. Great! It shows that this stuff is usable on a 
laptop.

This said, I would like to re-raise the importance of non-ext2 file system 
support, notably ReiserFS. It has been pointed out before, by Stephen Smalley, 
that this should in principle be easy to integrate (the per-node sec context 
needs to be stored in a file rather than in an unused field of the on-disk inode 
structure). However, I am not aware of anyone tackling this implementation.

Now, if someone could give me a few hints of where the additional code goes, I 
would like to volunteer some of my spare brain cycles to tackle this problem.
ReiserFS support on SELinux would certainly not only make my day.

Regards

Harald

**********************************************************
 Dr. Harald von Fellenberg  
 Chief Technologist        Global Sales Organisation
 Tel:    +41 1 908 9230    Sun Microsystems (Schweiz) AG
 Fax:    +41 1 908 9001    Javastr. 2 
 Mobile: +41 79 349 0393   CH-8604 Volketswil
 mailto:harald.von-fellenberg@sun.com
**********************************************************


--
You have received this message because you are subscribed to the selinux list.
If you no longer wish to subscribe, send mail to majordomo@tycho.nsa.gov with
the words "unsubscribe selinux" without quotes as the message.

^ permalink raw reply	[flat|nested] 7+ messages in thread

end of thread, other threads:[~2001-11-26 13:27 UTC | newest]

Thread overview: 7+ messages (download: mbox.gz follow: Atom feed
-- links below jump to the message on this page --
2001-11-19 16:15 SELinux and non-ext[23] file systems Harald von Fellenberg - Sun Switzerland Zurich - Technology Strategy Office
2001-11-19 16:37 ` Stephen Smalley
2001-11-22 10:36 ` Hans Reiser
2001-11-24  2:30   ` selinux, openssh, ipv6 jeff burson
2001-11-26 13:26     ` Stephen Smalley
  -- strict thread matches above, loose matches on Subject: below --
2001-11-19 14:51 SELinux and non-ext[23] file systems Harald von Fellenberg - Sun Switzerland Zurich - Technology Strategy Office
2001-11-19 14:57 ` Stephen Smalley

This is an external index of several public inboxes,
see mirroring instructions on how to clone and mirror
all data and code used by this external index.