From: Ingo Oeser <ingo.oeser@informatik.tu-chemnitz.de>
To: Greg KH <greg@kroah.com>
Cc: Gabor Kerenyi <wom@tateyama.hu>,
linux-kernel@vger.kernel.org, Chris Wright <chris@wirex.com>
Subject: Re: extended file permissions based on LSM
Date: Sat, 31 Aug 2002 09:57:47 +0200 [thread overview]
Message-ID: <20020831095747.A781@nightmaster.csn.tu-chemnitz.de> (raw)
In-Reply-To: <20020831052114.GA12082@kroah.com>; from greg@kroah.com on Fri, Aug 30, 2002 at 10:21:14PM -0700
On Fri, Aug 30, 2002 at 10:21:14PM -0700, Greg KH wrote:
> On Sat, Aug 31, 2002 at 06:16:04AM +0200, Gabor Kerenyi wrote:
> >
> > In this case we could have some very interesting (useful
> > or not who knows) features. For example if there are two
> > hardlinks for an inode in two different directories, the user
> > could get different rights for the file depending on the
> > path he reaches it.
>
> I think you can already do this with the existing LSM interface, you can
> always get the dentry for a given inode, right?
You get ALL dentries for the given inode. But I don't know,
whether such code traversion inode->i_dentry is valid in all situations.
Passing a dentry instead of inode is the easier variant, because
an dentry maps to exactly one inode, if it is a positive one[1]
The mapping from inode to dentries is 1:n and the thing the
poster wants is not possible with that, because the way the user
took to reach this inode is one of the n possibilities and we
don't know which one.
So this is a correctly pointed out design weakness: The way the
user took to reach the inode cannot be taken into account.
Regards
Ingo Oeser
[1] But we should never see permission checks for negative
dentries, since you cannot access what's not there ;-)
--
Science is what we can tell a computer. Art is everything else. --- D.E.Knuth
next prev parent reply other threads:[~2002-08-31 15:34 UTC|newest]
Thread overview: 10+ messages / expand[flat|nested] mbox.gz Atom feed top
2002-08-31 4:16 Gabor Kerenyi
2002-08-31 5:21 ` Greg KH
2002-08-31 7:09 ` Gabor Kerenyi
2002-09-01 0:23 ` Chris Wright
2002-08-31 7:57 ` Ingo Oeser [this message]
2002-09-01 0:26 ` Chris Wright
2002-09-01 15:55 ` Daniel Phillips
2002-09-01 23:08 ` Chris Wright
2002-09-02 0:20 ` Gabor Kerenyi
2002-08-31 23:50 ` Chris Wright
Reply instructions:
You may reply publicly to this message via plain-text email
using any one of the following methods:
* Save the following mbox file, import it into your mail client,
and reply-to-all from there: mbox
Avoid top-posting and favor interleaved quoting:
https://en.wikipedia.org/wiki/Posting_style#Interleaved_style
* Reply using the --to, --cc, and --in-reply-to
switches of git-send-email(1):
git send-email \
--in-reply-to=20020831095747.A781@nightmaster.csn.tu-chemnitz.de \
--to=ingo.oeser@informatik.tu-chemnitz.de \
--cc=chris@wirex.com \
--cc=greg@kroah.com \
--cc=linux-kernel@vger.kernel.org \
--cc=wom@tateyama.hu \
/path/to/YOUR_REPLY
https://kernel.org/pub/software/scm/git/docs/git-send-email.html
* If your mail client supports setting the In-Reply-To header
via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line
before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox
all inboxes | Powered by JetHome®