On Mon, 22 Nov 2004, Stephen Smalley wrote:

> Actually, I think we need a new flag field in the inode_security_struct
> to explicitly mark these "private" inodes for SELinux, so that
> inode_has_perm() can skip permission checking on them while still
> applying checks to any other inodes that may have the kernel SID (e.g.
> /proc/pid inodes for kernel threads).

Agreed.


- James
-- 
James Morris
<[EMAIL PROTECTED]>


Reply via email to