tech-kern archive

[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index][Old Index]

Re: Vnode scope implementation



hi,

> On Sun, Jul 19, 2009 at 10:34 AM, YAMAMOTO
> Takashi<yamt%mwd.biglobe.ne.jp@localhost> wrote:
> 
>> can you explain what's the point to call kauth when fs_decision is
>> already non-0?
>> i don't think it's a good idea to let kauth allow operations which
>> have already been rejected by the filesystem itself.
> 
> I think it's a very good idea, because then kauth(9) can implement MACs.

can you explain how it's required for MAC?  it isn't clear to me.

YAMAMOTO Takashi

> 
> -e.


Home | Main Index | Thread Index | Old Index