xfs
[Top] [All Lists]

Re: [patch] security. namespace

To: Chris PeBenito <pebenito@xxxxxxxxxx>
Subject: Re: [patch] security. namespace
From: Christoph Hellwig <hch@xxxxxxxxxxxxx>
Date: Mon, 1 Dec 2003 19:49:21 +0000
Cc: sandeen@xxxxxxx, linux-xfs@xxxxxxxxxxx
In-reply-to: <1070301662.7842.11.camel@chris.pebenito.net>; from pebenito@gentoo.org on Mon, Dec 01, 2003 at 12:01:02PM -0600
References: <1070301662.7842.11.camel@chris.pebenito.net>
Sender: linux-xfs-bounce@xxxxxxxxxxx
User-agent: Mutt/1.2.5.1i
On Mon, Dec 01, 2003 at 12:01:02PM -0600, Chris PeBenito wrote:
> Here is a patch against -test10 that adds an option for the security.
> namespace (controlled by a configure option), which is used by SELinux
> to store it's security labels.  I created this patch based off Tad
> Glines' (tadglines@xxxxxxxxxxx) 2.4 patch
> (http://www.glines.com/xfs.patch.bz2).  Please critique this, and if its
> ok, please consider for inclusion.
>
> I was warned on #xfs that this may break IRIX compatability, so there is
> a note in the Kconfig.  However Tad says that the security. attributes
> will show up in the user namespace on a standard XFS linux kernel, but I
> didn't verify.  He also mentioned that xfsdump and xfsrestore would need
> to be patched to support this.

a) please kill the silly ifdefs
b) without xfsdump support the patch is probably rather useless, you
   should be able to implement xfsdump support easily by looking at
   handling of the trusted xattrs.

Yes, this would be incompatible with IRIX asis, but IMHO it's fine because
this incompatiblity only affects people actually using security xattrs
which don't make sense on IRIX.


<Prev in Thread] Current Thread [Next in Thread>