Subject: Re: Kernel authorization in NetBSD
To: matthew sporleder <msporleder@gmail.com>
From: Elad Efrat <elad@NetBSD.org>
List: tech-security
Date: 04/18/2006 05:10:47
matthew sporleder wrote:

> Could you give some more hints on specific areas where you made
> changes so we can come up with some more direct tests?  You give some
> hints about layered filesystems, but where else should we look?
> Just doing random stuff and waiting for failures isn't as desirable.

If you're making heavy use of either NFS or layered file-systems (such
as umapfs/unionfs) you should be able to note if something is wrong. If
I knew exactly what might trip kauth(9) I'd test it myself... the reason
I posted is so that people could try their existing configurations and
report back if anything breaks.

Since the changes were made -- literally -- all around the kernel, I
can't be more specific...

Of course that if you run this code on your own machine doing the same
things you did prior to kauth(9) for a week it should be a good
measurement that things work well. :)

-e.

-- 
Elad Efrat