mirror of https://lore.kernel.org/lkml/
 help / color / mirror / Atom feed
From: Greg KH <greg@kroah.com>
To: Gabor Kerenyi <wom@tateyama.hu>
Cc: linux-kernel@vger.kernel.org, Chris Wright <chris@wirex.com>
Subject: Re: extended file permissions based on LSM
Date: Fri, 30 Aug 2002 22:21:14 -0700	[thread overview]
Message-ID: <20020831052114.GA12082@kroah.com> (raw)
In-Reply-To: <200208310616.04709.wom@tateyama.hu>

On Sat, Aug 31, 2002 at 06:16:04AM +0200, Gabor Kerenyi wrote:
> 
> In this case we could have some very interesting (useful
> or not who knows) features. For example if there are two
> hardlinks for an inode in two different directories, the user
> could get different rights for the file depending on the
> path he reaches it.

I think you can already do this with the existing LSM interface, you can
always get the dentry for a given inode, right?  I think there might be
a problem in determining the "real" path structure of the dentry all the
time due to mount locations, but that will be fixed up by the time 2.6
is out.

> To be honest I'd welcome if the whole file permisssion
> part were moved to LSM. It would allow us to override the
> currently implemented default behavior easily.

No!  One of the main goals of the LSM design was to not override the
current Linux permission behavior.  It can only deny access to things,
not be a permissive system of allowing access to things that the current
system denies.  See the many threads on the LSM mailing list for the
reasons behind this.

thanks,

greg k-h

  reply	other threads:[~2002-08-31  5:18 UTC|newest]

Thread overview: 10+ messages / expand[flat|nested]  mbox.gz  Atom feed  top
2002-08-31  4:16 Gabor Kerenyi
2002-08-31  5:21 ` Greg KH [this message]
2002-08-31  7:09   ` Gabor Kerenyi
2002-09-01  0:23     ` Chris Wright
2002-08-31  7:57   ` Ingo Oeser
2002-09-01  0:26     ` Chris Wright
2002-09-01 15:55       ` Daniel Phillips
2002-09-01 23:08         ` Chris Wright
2002-09-02  0:20           ` Gabor Kerenyi
2002-08-31 23:50 ` Chris Wright

Reply instructions:

You may reply publicly to this message via plain-text email
using any one of the following methods:

* Save the following mbox file, import it into your mail client,
  and reply-to-all from there: mbox

  Avoid top-posting and favor interleaved quoting:
  https://en.wikipedia.org/wiki/Posting_style#Interleaved_style

* Reply using the --to, --cc, and --in-reply-to
  switches of git-send-email(1):

  git send-email \
    --in-reply-to=20020831052114.GA12082@kroah.com \
    --to=greg@kroah.com \
    --cc=chris@wirex.com \
    --cc=linux-kernel@vger.kernel.org \
    --cc=wom@tateyama.hu \
    /path/to/YOUR_REPLY

  https://kernel.org/pub/software/scm/git/docs/git-send-email.html

* If your mail client supports setting the In-Reply-To header
  via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox

all inboxes | Powered by JetHome®