tech-kern archive

[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index][Old Index]

Re: Vnode scope implementation

On Sun, Jul 19, 2009 at 02:53:09PM +0300, Elad Efrat wrote:
> On Sun, Jul 19, 2009 at 10:34 AM, YAMAMOTO
> Takashi<> wrote:
> > can you explain what's the point to call kauth when fs_decision is
> > already non-0?
> > i don't think it's a good idea to let kauth allow operations which
> > have already been rejected by the filesystem itself.
> I think it's a very good idea, because then kauth(9) can implement MACs.

That doesn't make sense to me.  Operations rejected by the filesystem
itself are probably semantically invalid for that type of filesystem.

Thor Lancelot Simon                               
    "Even experienced UNIX users occasionally enter rm *.* at the UNIX
     prompt only to realize too late that they have removed the wrong
     segment of the directory structure." - Microsoft WSS whitepaper

Home | Main Index | Thread Index | Old Index