public inbox for linux-nfs@vger.kernel.org
 help / color / mirror / Atom feed
* nfs client uses different MAC policy or model
@ 2024-03-14 23:49 Daniel Walker (danielwa)
  2024-03-15 15:47 ` Jeff Layton
  0 siblings, 1 reply; 3+ messages in thread
From: Daniel Walker (danielwa) @ 2024-03-14 23:49 UTC (permalink / raw)
  To: selinux@vger.kernel.org
  Cc: xe-linux-external(mailer list), linux-nfs@vger.kernel.org


Hi,

It seems there is/was a problem using NFS security labels where the server and client use
different MAC policy or model. 

I was reading this page,

http://www.selinuxproject.org/page/Labeled_NFS/TODO#Label_Translation_Framework

It seems like this problem was known in 2009 when this page was written. Is
there a way to accomplish having extended attributes shared over NFS to a client
with different selinux policies ?

Maybe it's possible to allow the client to write local file context without
writing that down to the remote filesystem.

Thanks,
Daniel

^ permalink raw reply	[flat|nested] 3+ messages in thread

end of thread, other threads:[~2024-03-15 23:10 UTC | newest]

Thread overview: 3+ messages (download: mbox.gz follow: Atom feed
-- links below jump to the message on this page --
2024-03-14 23:49 nfs client uses different MAC policy or model Daniel Walker (danielwa)
2024-03-15 15:47 ` Jeff Layton
2024-03-15 23:09   ` Daniel Walker (danielwa)

This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox