Re: [PATCH] BSD Jail LSM (2/3)

From: Serge E. Hallyn
Date: Mon Sep 13 2004 - 11:42:24 EST


Quoting Alan Cox (alan@xxxxxxxxxxxxxxxxxxx):
> On Llu, 2004-09-13 at 00:33, Serge E. Hallyn wrote:
> > Right now one must choose between either an ipv4 or ipv6 interface.
> > Is typical ipv6 usage such that it would be preferable to be able to
> > specify one of each?
>
> Its normal to have both yes.
>
> A more interesting question is whether all of the "which socket for
> which use" stuff could be addressed by netfilter chains run at
> bind/connect time ?

You mean to add two new netfilter hooks? Would these then replace the
LSM hooks?

-serge
-
To unsubscribe from this list: send the line "unsubscribe linux-kernel" in
the body of a message to majordomo@xxxxxxxxxxxxxxx
More majordomo info at http://vger.kernel.org/majordomo-info.html
Please read the FAQ at http://www.tux.org/lkml/