Thread (6 messages) flat view 6 messages, 4 authors, 2004-10-08

Re: 2.6.9-rc2-mm4-VP-S7 - ksoftirq and selinux oddity

From: Stephen Smalley <hidden>
Date: 2004-10-08 11:26:09
Also in: lkml, selinux

On Fri, 2004-10-08 at 05:31, Luke Kenneth Casson Leighton wrote:
 an alternative possible solution is to get the packet _out_ from
 the interrupt context and have the aux pid comm exe information added.
No, the network permission checks are intentionally layered to match the
network protocol implementation.  There is a process-to-socket check
performed in process context when the data is received from the socket
by an actual process, but there is also the socket-to-netif/node/port
check performed in softirq context when the packet is received on the
socket from the network.

-- 
Stephen Smalley [off-list ref]
National Security Agency
Keyboard shortcuts
hback out one level
jnext message in thread
kprevious message in thread
ldrill in
Escclose help / fold thread tree
?toggle this help