Return-Path: Received: (majordomo@vger.kernel.org) by vger.kernel.org via listexpand id S1756571AbXJCWX3 (ORCPT ); Wed, 3 Oct 2007 18:23:29 -0400 Received: (majordomo@vger.kernel.org) by vger.kernel.org id S1753272AbXJCWXT (ORCPT ); Wed, 3 Oct 2007 18:23:19 -0400 Received: from web36605.mail.mud.yahoo.com ([209.191.85.22]:26370 "HELO web36605.mail.mud.yahoo.com" rhost-flags-OK-OK-OK-OK) by vger.kernel.org with SMTP id S1751491AbXJCWXS (ORCPT ); Wed, 3 Oct 2007 18:23:18 -0400 X-YMail-OSG: KTycftkVM1nZRtZUFPACARX.HYmwrCwJ_HpkCSb1wdNkML77X8oSeh1HRZTVB2VLFzwiZnrg_g-- X-RocketYMMF: rancidfat Date: Wed, 3 Oct 2007 15:23:15 -0700 (PDT) From: Casey Schaufler Reply-To: casey@schaufler-ca.com Subject: Re: [PATCH] Version 4 (2.6.23-rc8-mm2) Smack: Simplified Mandatory Access Control Kernel To: Al Viro , Casey Schaufler Cc: torvalds@osdl.org, linux-security-module@vger.kernel.org, linux-kernel@vger.kernel.org, akpm@osdl.org, paul.moore@hp.com In-Reply-To: <20071003205703.GM8181@ftp.linux.org.uk> MIME-Version: 1.0 Content-Type: text/plain; charset=US-ASCII Content-Transfer-Encoding: 7BIT Message-ID: <493479.85198.qm@web36605.mail.mud.yahoo.com> Sender: linux-kernel-owner@vger.kernel.org X-Mailing-List: linux-kernel@vger.kernel.org Content-Length: 4297 Lines: 112 --- Al Viro wrote: > On Wed, Oct 03, 2007 at 12:51:08PM -0700, Casey Schaufler wrote: > > > > Because you throw "simple" out the window when you require userland > > > > assistance to perform this function. > > > > > > Any more than having /tmp replaced with a symlink? > > > > Yes. By the way, there's nothing that really requires that you > > use a /smack symlink if you don't want to. /tmp can still be a > > real directory, a mount point, a symlink to /var/tmp, or whatever > > else you want it to be if that suits your needs better. For the > > simplest scenarios /tmp -> /smack/tmp -> /moldy/