Sebastien Roy writes: > > On Mon, 2009-03-02 at 16:37 -0500, James Carlson wrote: > > I think the libdladm model is weak in this area and could use some > > work. It should use auths correctly *and* do auditing when it grants > > access based on auths. It doesn't seem to do that. > > This part of the model could use improvements, but the part of the model > I'm pointing out that does work is not tying the set of things allowed > to issue operations to the data store's file permissions.
Yep; understood. That's not the right way to go at all. -- James Carlson, Solaris Networking <james.d.carlson at sun.com> Sun Microsystems / 35 Network Drive 71.232W Vox +1 781 442 2084 MS UBUR02-212 / Burlington MA 01803-2757 42.496N Fax +1 781 442 1677
