The SMACK64, SMACK64EXEC, and SMACK64MMAP labels are all handled
differently in untrusted mounts. This is confusing and
potentically problematic. Change this to handle them all the same
way that SMACK64 is currently handled; that is, read the label
from disk and check it at use time. For SMACK64
On Wed, Nov 18, 2015 at 11:12:51AM +1100, James Morris wrote:
> On Tue, 17 Nov 2015, Seth Forshee wrote:
>
> > + sbsp = inode->i_sb->s_security;
> > + if ((sbsp->smk_flags & SMK_SB_UNTRUSTED) &&
>
> Where is SMK_SB_UNTRUSTED defined?
>
> I can't see it in this patch series, mainline or