Return-Path: Received: (majordomo@vger.kernel.org) by vger.kernel.org via listexpand id S1754793AbYAIR1n (ORCPT ); Wed, 9 Jan 2008 12:27:43 -0500 Received: (majordomo@vger.kernel.org) by vger.kernel.org id S1752651AbYAIR1d (ORCPT ); Wed, 9 Jan 2008 12:27:33 -0500 Received: from mx1.redhat.com ([66.187.233.31]:38811 "EHLO mx1.redhat.com" rhost-flags-OK-OK-OK-OK) by vger.kernel.org with ESMTP id S1752625AbYAIR1c (ORCPT ); Wed, 9 Jan 2008 12:27:32 -0500 Organization: Red Hat UK Ltd. Registered Address: Red Hat UK Ltd, Amberley Place, 107-111 Peascod Street, Windsor, Berkshire, SI4 1TE, United Kingdom. Registered in England and Wales under Company Registration No. 3798903 From: David Howells In-Reply-To: <17868.1199897484@redhat.com> References: <17868.1199897484@redhat.com> <1197307397.18120.72.camel@moss-spartans.epoch.ncsc.mil> <1197305173.18120.60.camel@moss-spartans.epoch.ncsc.mil> <20071205193818.24617.79771.stgit@warthog.procyon.org.uk> <20071205193859.24617.36392.stgit@warthog.procyon.org.uk> <25037.1197306473@redhat.com> Cc: dhowells@redhat.com, Stephen Smalley , kmacmill@redhat.com, casey@schaufler-ca.com, linux-kernel@vger.kernel.org, selinux@tycho.nsa.gov, linux-security-module@vger.kernel.org Subject: Re: [PATCH 08/28] SECURITY: Allow kernel services to override LSM settings for task actions [try #2] X-Mailer: MH-E 8.0.3+cvs; nmh 1.2-20070115cvs; GNU Emacs 23.0.50 Date: Wed, 09 Jan 2008 17:27:18 +0000 Message-ID: <715.1199899638@redhat.com> To: unlisted-recipients:; (no To-header on input) Sender: linux-kernel-owner@vger.kernel.org List-ID: X-Mailing-List: linux-kernel@vger.kernel.org Content-Length: 850 Lines: 20 David Howells wrote: > Now, I recall the addition of another security class being mentioned, which > presumably would give something like: > > avc_has_perm(daemon_tsec->sid, nominated_sid, > SECCLASS_CACHE, CACHE__USE_AS_OVERRIDE, NULL); Hmmmm... I can't see how to add a new security class. I can see that security classes are defined in various autogenerated header files, but autogenerated from what? The "This file is automatically generated. Do not edit." message at the top of these files seems to belie the fact they're actually checked in to GIT as is. David -- To unsubscribe from this list: send the line "unsubscribe linux-kernel" in the body of a message to majordomo@vger.kernel.org More majordomo info at http://vger.kernel.org/majordomo-info.html Please read the FAQ at http://www.tux.org/lkml/