All of lore.kernel.org
 help / color / mirror / Atom feed
* [RFC PATCH 0/2] Series short description
@ 2007-09-25 20:48 Paul Moore
  2007-09-25 20:48 ` [RFC PATCH 1/2] [SELINUX] Add a functionality version number Paul Moore
                   ` (2 more replies)
  0 siblings, 3 replies; 28+ messages in thread
From: Paul Moore @ 2007-09-25 20:48 UTC (permalink / raw)
  To: selinux

This patchset has two patches in it which I would like to get some feedback
on.  The first patch adds a functionality/compatability version number to the
policy so that we can add new functionality to the kernel which would lie
dormant until the correct policy was loaded - it is not intended to replace
Eric's undefined classes/perms work but to compliment it.  The second patch
is the first step towards a single set of access checks for the different
peer labeling mechanisms, NetLabel and labeled IPsec, by providing a single
function to determine the peer label of an incoming packet.  The ideas behind
both patches have been discussed in the past, but I'd like to see if there
are any new concerns now that people can see what an implementation would
look like.  I'm particularly interested in people's take on the policy
changes.  The approach presented in this patch seems to be sane and low risk
to me but I'm hoping some of you with more experience tinkering with the
policy code could take a look and comment.

This is an RFC quality patchset which means it does boot and passes a few
simple tests but will most likely shave your cat if your turn your back to it
for more than a few minutes.

--
paul moore
linux security @ hp


--
This message was distributed to subscribers of the selinux mailing list.
If you no longer wish to subscribe, send mail to majordomo@tycho.nsa.gov with
the words "unsubscribe selinux" without quotes as the message.

^ permalink raw reply	[flat|nested] 28+ messages in thread

end of thread, other threads:[~2007-09-26 20:46 UTC | newest]

Thread overview: 28+ messages (download: mbox.gz follow: Atom feed
-- links below jump to the message on this page --
2007-09-25 20:48 [RFC PATCH 0/2] Series short description Paul Moore
2007-09-25 20:48 ` [RFC PATCH 1/2] [SELINUX] Add a functionality version number Paul Moore
2007-09-25 21:12   ` Eric Paris
2007-09-25 21:16     ` Paul Moore
2007-09-25 20:48 ` [RFC PATCH 2/2] [SELINUX] Better integration between peer labeling subsystems Paul Moore
2007-09-25 21:37   ` Eric Paris
2007-09-25 22:01     ` Paul Moore
2007-09-25 22:38   ` James Morris
2007-09-25 22:48     ` Paul Moore
2007-09-26 12:41   ` Stephen Smalley
2007-09-26 15:46     ` Paul Moore
2007-09-26 16:18       ` Paul Moore
2007-09-25 22:28 ` [RFC PATCH 0/2] Series short description James Morris
2007-09-25 22:38   ` Paul Moore
2007-09-26  2:19     ` Joshua Brindle
2007-09-26  3:12       ` Paul Moore
2007-09-26 13:18         ` Joshua Brindle
2007-09-26 13:29         ` Stephen Smalley
2007-09-26 16:00           ` Paul Moore
2007-09-26 16:43             ` Joshua Brindle
2007-09-26 16:48               ` Stephen Smalley
2007-09-26 16:54               ` Paul Moore
2007-09-26 16:57                 ` Joshua Brindle
2007-09-26 17:04                   ` Paul Moore
2007-09-26 20:39                     ` Joshua Brindle
2007-09-26 20:46                       ` Paul Moore
2007-09-26 20:36           ` Joshua Brindle
2007-09-26 20:32             ` Stephen Smalley

This is an external index of several public inboxes,
see mirroring instructions on how to clone and mirror
all data and code used by this external index.