Re: [RFC 0/28] Patches to pass vfsmount to LSM inode security hooks

[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]

 



On Mon, 2007-02-05 at 18:44 +0000, Christoph Hellwig wrote:
> Just FYI:  Al was very opposed to the idea of passing the vfsmount to
> the vfs_ helpers, so you should discuss this with him.
> 
> Looking at the actual patches I see you're lazy in a lot of places.
> Please make sure that when you introduce a vfsmount argument somewhere
> that it is _always_ passed and not just when it's conveniant.  Yes, that's
> more work, but then again if you're not consistant anyone half-serious
> will laught at a security model using this infrasturcture.

nfsd in particular tends to be a bit lazy about passing around vfsmount
info. Forcing it to do so should not be hard since the vfsmount is
already cached in the "struct export" (which can be found using the
filehandle). It will take a bit of re-engineering in order to pass that
information around inside the nfsd code, though.

Note also that it might be nice to enforce the vfsmount argument by
replacing the existing dentry parameters with a struct path instead of
adding an extra reference to the vfsmount to existing functions.

Cheers,
  Trond

-
To unsubscribe from this list: send the line "unsubscribe linux-kernel" in
the body of a message to [email protected]
More majordomo info at  http://vger.kernel.org/majordomo-info.html
Please read the FAQ at  http://www.tux.org/lkml/

[Index of Archives]     [Kernel Newbies]     [Netfilter]     [Bugtraq]     [Photo]     [Stuff]     [Gimp]     [Yosemite News]     [MIPS Linux]     [ARM Linux]     [Linux Security]     [Linux RAID]     [Video 4 Linux]     [Linux for the blind]     [Linux Resources]
  Powered by Linux