>I'm happy with this case as specified so +1.
>
>I'm going on the assumption that this works for all filesystems that 
>privileges currently work for.


Thanks,

At this point the implementation is such that if DAC permission is
granted, then we never call any of the secpolicy routines.

Clearly, for these privileges to work the filesystems need to be changed;
when this project is completed, we will have complete support for the
filesystems in OS-Net plus whatever support we will implement in the
VOP_* layer.

Other filesystems such as VxFS, QFS, SamFS will need to be modified.

Casper


Reply via email to