* [PATCH 0/3] secid reconciliation-v01: Repost patchset with updates
@ 2006-08-24 17:50 ` Venkat Yekkirala
0 siblings, 0 replies; 4+ messages in thread
From: Venkat Yekkirala @ 2006-08-24 17:50 UTC (permalink / raw)
To: netdev, selinux; +Cc: jmorris, sds, chanson
The following are the changes included in this patchset since the previous post:
- Use SELinux transition rules instead of precedence when reconciling the secid's
making it flexible/policy-driven; xfrm secid would prevail by default.
- Change the naming of access vector perms to flow_in and flow_out.
- Make selinux_xfrm_sock_rcv_skb checks conditional on compat_net.
- Switch selinux_inet_conn_request to use secmark; cipso is still allowed to
override secmark currently in this regard (will rely on Paul Moore at HP
to bring cipso into the reconciliation path).
This patchset is relative to David Miller's net-2.6.19.git.
Please consider for inclusion in 2.6.19.
--
This message was distributed to subscribers of the selinux mailing list.
If you no longer wish to subscribe, send mail to majordomo@tycho.nsa.gov with
the words "unsubscribe selinux" without quotes as the message.
^ permalink raw reply [flat|nested] 4+ messages in thread
* [PATCH 0/3] secid reconciliation-v01: Repost patchset with updates
@ 2006-08-24 17:50 ` Venkat Yekkirala
0 siblings, 0 replies; 4+ messages in thread
From: Venkat Yekkirala @ 2006-08-24 17:50 UTC (permalink / raw)
To: netdev, selinux; +Cc: jmorris, sds, chanson
The following are the changes included in this patchset since the previous post:
- Use SELinux transition rules instead of precedence when reconciling the secid's
making it flexible/policy-driven; xfrm secid would prevail by default.
- Change the naming of access vector perms to flow_in and flow_out.
- Make selinux_xfrm_sock_rcv_skb checks conditional on compat_net.
- Switch selinux_inet_conn_request to use secmark; cipso is still allowed to
override secmark currently in this regard (will rely on Paul Moore at HP
to bring cipso into the reconciliation path).
This patchset is relative to David Miller's net-2.6.19.git.
Please consider for inclusion in 2.6.19.
^ permalink raw reply [flat|nested] 4+ messages in thread
* Re: [PATCH 0/3] secid reconciliation-v01: Repost patchset with updates
2006-08-24 17:50 ` Venkat Yekkirala
@ 2006-08-24 19:37 ` James Morris
-1 siblings, 0 replies; 4+ messages in thread
From: James Morris @ 2006-08-24 19:37 UTC (permalink / raw)
To: Venkat Yekkirala; +Cc: netdev, selinux, sds, chanson
On Thu, 24 Aug 2006, Venkat Yekkirala wrote:
> The following are the changes included in this patchset since the previous
> post:
>
> - Use SELinux transition rules instead of precedence when reconciling the
> secid's
> making it flexible/policy-driven; xfrm secid would prevail by default.
> - Change the naming of access vector perms to flow_in and flow_out.
> - Make selinux_xfrm_sock_rcv_skb checks conditional on compat_net.
> - Switch selinux_inet_conn_request to use secmark; cipso is still allowed to
> override secmark currently in this regard (will rely on Paul Moore at HP
> to bring cipso into the reconciliation path).
I like these changes, but wondering why you haven't supplied code for the
outbound case ?
- James
--
James Morris
<jmorris@namei.org>
--
This message was distributed to subscribers of the selinux mailing list.
If you no longer wish to subscribe, send mail to majordomo@tycho.nsa.gov with
the words "unsubscribe selinux" without quotes as the message.
^ permalink raw reply [flat|nested] 4+ messages in thread
* Re: [PATCH 0/3] secid reconciliation-v01: Repost patchset with updates
@ 2006-08-24 19:37 ` James Morris
0 siblings, 0 replies; 4+ messages in thread
From: James Morris @ 2006-08-24 19:37 UTC (permalink / raw)
To: Venkat Yekkirala; +Cc: netdev, selinux, sds, chanson
On Thu, 24 Aug 2006, Venkat Yekkirala wrote:
> The following are the changes included in this patchset since the previous
> post:
>
> - Use SELinux transition rules instead of precedence when reconciling the
> secid's
> making it flexible/policy-driven; xfrm secid would prevail by default.
> - Change the naming of access vector perms to flow_in and flow_out.
> - Make selinux_xfrm_sock_rcv_skb checks conditional on compat_net.
> - Switch selinux_inet_conn_request to use secmark; cipso is still allowed to
> override secmark currently in this regard (will rely on Paul Moore at HP
> to bring cipso into the reconciliation path).
I like these changes, but wondering why you haven't supplied code for the
outbound case ?
- James
--
James Morris
<jmorris@namei.org>
^ permalink raw reply [flat|nested] 4+ messages in thread
end of thread, other threads:[~2006-08-24 19:37 UTC | newest]
Thread overview: 4+ messages (download: mbox.gz follow: Atom feed
-- links below jump to the message on this page --
2006-08-24 17:50 [PATCH 0/3] secid reconciliation-v01: Repost patchset with updates Venkat Yekkirala
2006-08-24 17:50 ` Venkat Yekkirala
2006-08-24 19:37 ` James Morris
2006-08-24 19:37 ` James Morris
This is an external index of several public inboxes,
see mirroring instructions on how to clone and mirror
all data and code used by this external index.