Re: [PATCH][SELINUX] 3/7 Add node controls

From: James Morris (jmorris_at_redhat.com)
Date: 01/09/04

  • Next message: Grant Grundler: "Re: [RFC] Relaxed PIO read vs. DMA write ordering"
    Date:	Fri, 9 Jan 2004 15:17:40 -0500 (EST)
    To: Arkadiusz Miskiewicz <arekm@pld-linux.org>
    
    

    On Fri, 9 Jan 2004, Arkadiusz Miskiewicz wrote:

    > > Like the previous patch, similar functionality was present in earlier
    > > SELinux implementations; this is a rework within the constraints of the
    > > LSM hooks present in the mainline kernel.
    > But only for IPv4 right? What about IPv6 part - is SELinux able to deal with
    > IPv6 at all?

    Not at this level yet. There are socket controls which provide coverage
    all protocols, and finer grained controls for IPv4 and Unix. Duplication
    of the IPv4-specific controls for IPv6 is expected to be implemented soon.

    - James

    -- 
    James Morris
    <jmorris@redhat.com>
    -
    To unsubscribe from this list: send the line "unsubscribe linux-kernel" in
    the body of a message to majordomo@vger.kernel.org
    More majordomo info at  http://vger.kernel.org/majordomo-info.html
    Please read the FAQ at  http://www.tux.org/lkml/
    

  • Next message: Grant Grundler: "Re: [RFC] Relaxed PIO read vs. DMA write ordering"

    Relevant Pages

    • How NOT to have already compiled modules (auto)load?
      ... I have a laptop with USB CD-ROM that is very rarely attached/used. ... Or even better, to be able to manually modprobe the so called blacklisted ones, but any other means to load them should fail? ... Another example is the ipv6, which is difficult to unload at best, as sometimes I want to test something without ipv6. ... send the line "unsubscribe linux-kernel" in ...
      (Linux-Kernel)
    • Re: [PATCH][SELINUX] 3/7 Add node controls
      ... > which allows network traffic to be controlled on the basis of remote ... > SELinux implementations; this is a rework within the constraints of the ... IPv6 at all? ... send the line "unsubscribe linux-kernel" in ...
      (Linux-Kernel)
    • Re: 2.6.8.1 - unresolved xfrm symbols in ip6_tunnel
      ... Fix bug #3200 ... tristate "IPv6: IPv6-in-IPv6 tunnel" ... depends on IPV6 ... send the line "unsubscribe linux-kernel" in ...
      (Linux-Kernel)
    • Re: 2.6.7-rc3: waiting for eth0 to become free
      ... static void ipv4_link_failure(struct sk_buff *skb) ... However, reverting these ... changes breaks IPv6 a little bit for me. ... send the line "unsubscribe linux-kernel" in ...
      (Linux-Kernel)
    • Tons of "ICMPv6 checksum failed" in the logs
      ... With 2.6.5 I started experiemnting with IPv6 and now most everything is working OK. ... However I found tons of the following in kernel logs: ... send the line "unsubscribe linux-kernel" in ...
      (Linux-Kernel)