2008-01-17 23:02:42

by David Howells

Subject: Re: [NFS] [PATCH 06b/26] Security: Make NFSD work with detached security

David Howells <[email protected]> wrote:

> J. Bruce Fields <[email protected]> wrote:
> > Just curious--why? Are get_kernel_security(), etc., particularly
> > expensive?
> It involves a kmalloc(). That means an extra possibility for an error. Plus
> it may allow you to cache the result of checking whether, say, SELinux
> security labels are allowed to be set when passed over NFS (if such is
> possible).

Apart from that, though, no, it's not particularly expensive.


