Re: [RESEND][RFC][PATCH 2/7] implementation of LSM hooks

From: Arjan van de Ven
Date: Wed Apr 19 2006 - 01:23:39 EST


On Tue, 2006-04-18 at 16:09 -0700, Casey Schaufler wrote:
> --- Alan Cox <alan@xxxxxxxxxxxxxxxxxxx> wrote:
>
> > ... A file name is a pretty
> > meaningless object in Unixspace ...
>
> Stephen is right that the inode is the object.
> Crispin is right that people care about path names.
>
> The linux-audit folks have been hashing this
> about good and hard. It is true that both the
> pathname /etc/shadow and the inode it represents
> are interesting from various secuirty viewpoints.
> If you insist on either being the definitive
> security referent you will be wrong about half
> the time.

just that LSM is inode based ;)


-
To unsubscribe from this list: send the line "unsubscribe linux-kernel" in
the body of a message to majordomo@xxxxxxxxxxxxxxx
More majordomo info at http://vger.kernel.org/majordomo-info.html
Please read the FAQ at http://www.tux.org/lkml/