Research Menu

.
Skip Search Box

SELinux Mailing List

Re: [RFC][PATCH] collect security labels on user processes generating audit messages

From: James Morris <jmorris_at_namei.org>
Date: Thu, 9 Feb 2006 12:03:10 -0500 (EST)


On Thu, 9 Feb 2006, Timothy R. Chavez wrote:

> > Please look at the way I intend to export SELinux APIs in:
> > http://people.redhat.com/jmorris/selinux/skfilter/kernel/12-skfilter-selinux-exports.patch
>
> This looks good. Do you have a schedule for releasing this?

No, it's blocked on some core netfilter changes. I suggest following its format, though, if needed.

> > I wonder if it might be better to use the security context directly.
> >
>
> I think it'd be the simplest solution, but I was a bit weary about
> adding a string param... I thought using an integer might be the path of
> least resistance :)

As previousl mentioned, also consider adding a security blob to the netlink params.

> > security_task_getsid() doesn't exist.
> >
> > You created security_task_getsecurity(), which retrieves the security
> > context.
>
> Actually, security_task_getsid() does exist (or did exist last time I
> updated the viro/audit-2.6 git tree).
>
> http://www.promethos.org/lxr/http/ident?i=security_task_getsid

Oh, ok.

Where is security_task_getsecurity() used, then?

  • James -- James Morris <jmorris@namei.org>
--
This message was distributed to subscribers of the selinux mailing list.
If you no longer wish to subscribe, send mail to majordomo@tycho.nsa.gov with
the words "unsubscribe selinux" without quotes as the message.
Received on Thu 9 Feb 2006 - 12:04:19 EST
 

Date Posted: Jan 15, 2009 | Last Modified: Jan 15, 2009 | Last Reviewed: Jan 15, 2009

 
bottom

National Security Agency / Central Security Service