Research
.
Skip Search Box

SELinux Mailing List

Re: XFS and SE Linux

From: Russell Coker <russell_at_coker.com.au>
Date: Wed, 10 Mar 2004 01:04:46 +1100


On Wed, 10 Mar 2004 01:00, Stephen Smalley <sds@epoch.ncsc.mil> wrote:
> On Tue, 2004-03-09 at 08:14, Russell Coker wrote:
> > Currently in SE Linux the contexts for files are of the form
> > "system_u:object_r:file_t", why not express them on disk as
> > "system_u:file_t"? Saving 9 bytes in this manner could make some of them
> > fit into a 256 byte Inode in XFS which would be a significant advantage.
> > Also for Ext2/Ext3 it will save some space as well.
>
> Why not just fix XFS to handle xattrs sanely?

I have sent an email to some SGI people with some ideas that I think would be beneficial. However doing such changes would take some time. They need to have some sort of compatibility flag in the on-disk structure, some new data structures on disk, and a new fsck that understands both old and new formats. This isn't going to happen overnight. While a change to the way security.selinux is used by the kernel can be implemented much more easily.

-- 
http://www.coker.com.au/selinux/   My NSA Security Enhanced Linux packages
http://www.coker.com.au/bonnie++/  Bonnie++ hard drive benchmark
http://www.coker.com.au/postal/    Postal SMTP/POP benchmark
http://www.coker.com.au/~russell/  My home page

--
This message was distributed to subscribers of the selinux mailing list.
If you no longer wish to subscribe, send mail to majordomo@tycho.nsa.gov with
the words "unsubscribe selinux" without quotes as the message.
Received on Tue 9 Mar 2004 - 09:06:22 EST
 

Date Posted: Jan 15, 2009 | Last Modified: Jan 15, 2009 | Last Reviewed: Jan 15, 2009

 
bottom

National Security Agency / Central Security Service