All of lore.kernel.org
 help / color / mirror / Atom feed
From: Karl MacMillan <kmacmillan@mentalrootkit.com>
To: Joshua Brindle <jbrindle@tresys.com>
Cc: selinux@tycho.nsa.gov, sds@tycho.nsa.gov
Subject: Re: [PATCH 2/2] Refactor expansion of avtab
Date: Thu, 27 Jul 2006 10:36:03 -0400	[thread overview]
Message-ID: <44C8CF53.6040009@mentalrootkit.com> (raw)
In-Reply-To: <6FE441CD9F0C0C479F2D88F959B01588298D4F@exchange.columbia.tresys.com>

Joshua Brindle wrote:
>> From: Karl MacMillan [mailto:kmacmillan@mentalrootkit.com] 
>>
>>     
>> Poorly named function - are neverallows av rules or not? If 
>> they are not the function needs a more generic name. This is 
>> continuing the confusing practice of sometimes calling just 
>> allow and audit rules av rules and sometimes using it to mean 
>> more rule types.
>>
>>     
>
> Have any suggestions? We couldn't think of a really good name either.
>
>   

I vote we start using avrules to mean allow, audit, and neverallow - 
i.e., based on their common syntax. That would argue for the define 
changing in the other patch.

>> This can be in place or out of place (i.e., out can be the 
>> same as base)? A comment describing how this function can be 
>> used is needed, including the fact that the typemap must be 
>> "special" for an in-place expand, correct?
>>
>>     
>
> Either, it is out of place for the current usage and in place for
> setools. Talking about a special typemap is out of context here. Maybe
> more comments are needed. No need to ditch this patch though, we can
> apply some comments on top of it.
>
>   

Why is talking about a specific typemap out of place? Just give the user 
a hint that if they want to do in-place expansion what the typemap will 
be. Where is the real documentation for typemap going to go?

>> Object classes and permissions will never need to be mapped 
>> for an out of place expansion?
>>
>>     

What about this question?

Karl

--
This message was distributed to subscribers of the selinux mailing list.
If you no longer wish to subscribe, send mail to majordomo@tycho.nsa.gov with
the words "unsubscribe selinux" without quotes as the message.

      reply	other threads:[~2006-07-27 14:36 UTC|newest]

Thread overview: 4+ messages / expand[flat|nested]  mbox.gz  Atom feed  top
2006-07-25 14:56 [PATCH 2/2] Refactor expansion of avtab Joshua Brindle
2006-07-25 16:16 ` Karl MacMillan
2006-07-25 16:55   ` Joshua Brindle
2006-07-27 14:36     ` Karl MacMillan [this message]

Reply instructions:

You may reply publicly to this message via plain-text email
using any one of the following methods:

* Save the following mbox file, import it into your mail client,
  and reply-to-all from there: mbox

  Avoid top-posting and favor interleaved quoting:
  https://en.wikipedia.org/wiki/Posting_style#Interleaved_style

* Reply using the --to, --cc, and --in-reply-to
  switches of git-send-email(1):

  git send-email \
    --in-reply-to=44C8CF53.6040009@mentalrootkit.com \
    --to=kmacmillan@mentalrootkit.com \
    --cc=jbrindle@tresys.com \
    --cc=sds@tycho.nsa.gov \
    --cc=selinux@tycho.nsa.gov \
    /path/to/YOUR_REPLY

  https://kernel.org/pub/software/scm/git/docs/git-send-email.html

* If your mail client supports setting the In-Reply-To header
  via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line before the message body.
This is an external index of several public inboxes,
see mirroring instructions on how to clone and mirror
all data and code used by this external index.