Re: [AppArmor 39/45] AppArmor: Profile loading and manipulation, pathname matching

From: Pavel Machek
Date: Mon Jun 11 2007 - 07:01:08 EST


> ACPI should have taught everyone that sometimes putting an interpreter in
> the kernel really is the best option. looking at the problems of bouncing
> back out to userspace for file creation and renames it looks like a regex
> in the kernel is a lot safer and more reliable.

What do ACPI and AA have in common?

* they both start with A

* there are both nightmare

* they both put interpretter into kernel

