From mboxrd@z Thu Jan 1 00:00:00 1970 From: James Morris Subject: Re: r-o bind in nfsd Date: Thu, 27 Mar 2008 08:35:03 +1100 (EST) Message-ID: References: <20080321155451.GU10722@ZenIV.linux.org.uk> <20080321163520.GV10722@ZenIV.linux.org.uk> <18408.26863.617591.836548@notabene.brown> <200803252045.CGB04105.HLSQFOJMtOFVOF@I-love.SAKURA.ne.jp> <57096.192.168.1.70.1206484328.squirrel@neil.brown.name> <1206533042.3302.266.camel@moss-spartans.epoch.ncsc.mil> <20080326164753.GA20578@sergelap.ibm.com> Mime-Version: 1.0 Content-Type: TEXT/PLAIN; charset=US-ASCII Cc: Stephen Smalley , NeilBrown , Tetsuo Handa , miklos@szeredi.hu, viro@zeniv.linux.org.uk, haveblue@us.ibm.com, linux-fsdevel@vger.kernel.org, linux-kernel@vger.kernel.org, akpm@linux-foundation.org, hch@infradead.org, linux-security-module@vger.kernel.org To: "Serge E. Hallyn" Return-path: Received: from namei.org ([69.55.235.186]:36629 "EHLO us.intercode.com.au" rhost-flags-OK-OK-OK-FAIL) by vger.kernel.org with ESMTP id S1756240AbYCZVnD (ORCPT ); Wed, 26 Mar 2008 17:43:03 -0400 In-Reply-To: <20080326164753.GA20578@sergelap.ibm.com> Sender: linux-fsdevel-owner@vger.kernel.org List-ID: On Wed, 26 Mar 2008, Serge E. Hallyn wrote: > Not only that, but containers require an LSM to provide user isolation > and root containment. You mean LSM hooks, which various LSM could utilize if desired, right? - James -- James Morris