From mboxrd@z Thu Jan 1 00:00:00 1970 Return-Path: Received: (majordomo@vger.kernel.org) by vger.kernel.org via listexpand id S1757323AbXGBW4R (ORCPT ); Mon, 2 Jul 2007 18:56:17 -0400 Received: (majordomo@vger.kernel.org) by vger.kernel.org id S1755456AbXGBW4D (ORCPT ); Mon, 2 Jul 2007 18:56:03 -0400 Received: from mx1.redhat.com ([66.187.233.31]:36661 "EHLO mx1.redhat.com" rhost-flags-OK-OK-OK-OK) by vger.kernel.org with ESMTP id S1754855AbXGBW4B (ORCPT ); Mon, 2 Jul 2007 18:56:01 -0400 Message-ID: <4689826C.5050800@redhat.com> Date: Mon, 02 Jul 2007 18:55:40 -0400 From: Rik van Riel Organization: Red Hat, Inc User-Agent: Thunderbird 1.5.0.7 (X11/20061008) MIME-Version: 1.0 To: Davide Libenzi CC: Ulrich Drepper , Andy Isaacson , Kyle Moffett , Linux Kernel Mailing List Subject: Re: [patch 0/4] MAP_NOZERO v2 - VM_NOZERO/MAP_NOZERO early summer madness References: <20070629193954.GL9157@hexapodia.org> <8F40BE4A-BD38-4C3F-B77D-35661E84C553@mac.com> <20070702190043.GN9157@hexapodia.org> <46894BE6.1040302@redhat.com> In-Reply-To: Content-Type: text/plain; charset=UTF-8; format=flowed Content-Transfer-Encoding: 7bit Sender: linux-kernel-owner@vger.kernel.org X-Mailing-List: linux-kernel@vger.kernel.org Davide Libenzi wrote: > On Mon, 2 Jul 2007, Ulrich Drepper wrote: > >> On 7/2/07, Rik van Riel wrote: >>> That should not happen. The default SELinux configuration >>> in Fedora (and Debian?) runs a few daemons in their own >>> restricted modes and has most of the system running in >>> unconfined_t, including the majority of user programs. >> This is the state as of F7. This will change hopefully soon. >> Programs like firefox run by normal users must be confined, to. Any >> tests using security must be fast, it's not something which is done >> only for a few apps. > > The strong requirement would be that the cookie is not a bit longer than > sizeof(unsigned long). You could easily replace the cookie with a pointer to a free page pool. -- Politics is the struggle between those who want to make their country the best in the world, and those who believe it already is. Each group calls the other unpatriotic.