Re: [RFC] [PATCH] merge *_vm_enough_memory()s into a common helper

From: Chris Wright
Date: Tue Jan 04 2005 - 17:31:43 EST


* Stephen Smalley (sds@xxxxxxxxxxxxxx) wrote:
> On Tue, 2005-01-04 at 17:17, Chris Wright wrote:
> > * Serge E. Hallyn (serue@xxxxxxxxxx) wrote:
> >
> > I'm fine with this with a few nits. Although I don't think it will apply
> > to current bk which has merge error in this area right now. Stephen,
> > are you ok with the way this one generates audit messages?
>
> Looks like the patch (with suggested fixes) will preserve the current
> behavior, i.e. no audit message generation for SELinux from the
> vm_enough_memory hook, while still auditing real uses of CAP_SYS_ADMIN
> elsewhere. That is what we want.

Good, thanks.
-chris
--
Linux Security Modules http://lsm.immunix.org http://lsm.bkbits.net
-
To unsubscribe from this list: send the line "unsubscribe linux-kernel" in
the body of a message to majordomo@xxxxxxxxxxxxxxx
More majordomo info at http://vger.kernel.org/majordomo-info.html
Please read the FAQ at http://www.tux.org/lkml/