Re: [PATCH 2/3] CRED: Split the task security data and move part of it into struct cred

From: David Howells
Date: Thu Sep 20 2007 - 13:49:59 EST


David Howells <dhowells@xxxxxxxxxx> wrote:

> > So it sounds like what you'd be happiest with would be a separate task
> > struct hand crafted to he the right "object" and "subject" attributes.

Actually, that whilst that is sort of feasible for CacheFiles[*], it is not
really feasible for NFSd. NFSd possesses a set of daemons that have a
standard objective context and substitute a lot of different subjective
contexts as they perform VFS operations on behalf of remote clients.

[*] But in practice quite icky from other points of view.

David
-
To unsubscribe from this list: send the line "unsubscribe linux-kernel" in
the body of a message to majordomo@xxxxxxxxxxxxxxx
More majordomo info at http://vger.kernel.org/majordomo-info.html
Please read the FAQ at http://www.tux.org/lkml/