Research
.
Skip Search Box

SELinux Mailing List

Re: [RFC] [PATCH]

From: Stephen Smalley <sds_at_tycho.nsa.gov>
Date: Fri, 17 Feb 2006 13:26:29 -0500


On Fri, 2006-02-17 at 10:04 -0600, Dustin Kirkland wrote:
> On Fri, 2006-02-17 at 08:43 -0600, Darrel Goeddel wrote:
> > It would seem to me that we need the current functionality of keeping all rules
> > that are set up and revalidating them upon policy loads. If we don't do it here,
> > it would need to be done at the audit layer - it might not be as pretty there.
>
>
> I don't know... My first thoughts are that it seems like the audit
> layer should be ignorant of policy loads/reloads--that's not really it's
> business.

Disagree - it is caching policy information, and thus should register a callback for notification of reloads so that it can re-process its audit rules at that time, similar to the netif table. That would presumably address the locking concern as well.

-- 
Stephen Smalley
National Security Agency


--
This message was distributed to subscribers of the selinux mailing list.
If you no longer wish to subscribe, send mail to majordomo@tycho.nsa.gov with
the words "unsubscribe selinux" without quotes as the message.
Received on Fri 17 Feb 2006 - 13:20:50 EST
 

Date Posted: Jan 15, 2009 | Last Modified: Jan 15, 2009 | Last Reviewed: Jan 15, 2009

 
bottom

National Security Agency / Central Security Service