2016-06-27 13:40:21

by Daniel Jurgens

[permalink] [raw]
Subject: [refpolicy] [PATCH 1/1] flask: Add classes and SIDs for InfiniBand support

On 6/25/2016 12:02 PM, Chris PeBenito wrote:
> On 06/23/16 15:47, Dan Jurgens wrote:
>> From: Daniel Jurgens <[email protected]>
>>
>> Add new classes, access vectors, SIDs required for SELinux to provide
>> access control for InfiniBand. Add stub policy so refpolicy still
>> compiles. Useful policy will be added after the SELinux kernel and
>> userspace changes are in place.
>
> This will have to wait until the corresponding code changes start making
> their way upstream. I don't want to merge any new classes, and even
> more so, initial SIDs, until I'm confident it won't be changing.

Sure, I will resubmit after the kernel changes are accepted upstream.

>
> I'm not sure that a new infiniband module makes sense. I could see it
> going in corenetwork.
>

I can move it there when I do resubmit.