Research
.
Skip Search Box

SELinux Mailing List

Re: dynamic context transitions

From: Luke Kenneth Casson Leighton <lkcl_at_lkcl.net>
Date: Wed, 3 Nov 2004 15:38:21 +0000


On Tue, Nov 02, 2004 at 08:47:48AM -0500, Stephen Smalley wrote:
> On Mon, 2004-11-01 at 17:58, Luke Kenneth Casson Leighton wrote:
> > e.g. if you _do_ implement exec_mls_up/downgrade() then you
> > can actually express that simply as a domain_auto_trans()
> > and an exec()?
> >
> > which _actually_ means that you really should abandon MLS altogether
> > and rewrite your applications to use selinux TE instead?
> >
> > ... i'm just following a logical progression here, but i feel i must
> > have missed something. clues anyone?
>
> TE is an access matrix, so it can represent a MLS policy, but the
> resulting representation would be huge for any significant number of MLS
> levels.

 so, this is again a bit like the "groups" argument - the one  where the number of bits representing the access matrix could  go exponential [and impractical]?

 l.

--
This message was distributed to subscribers of the selinux mailing list.
If you no longer wish to subscribe, send mail to majordomo@tycho.nsa.gov with
the words "unsubscribe selinux" without quotes as the message.
Received on Wed 3 Nov 2004 - 10:27:59 EST
 

Date Posted: Jan 15, 2009 | Last Modified: Jan 15, 2009 | Last Reviewed: Jan 15, 2009

 
bottom

National Security Agency / Central Security Service