Re: SELinux and non-ext[23] file systems

From: Stephen Smalley <sds_at_tislabs.com>
Date: Mon, 19 Nov 2001 09:57:39 -0500 (EST)

On Mon, 19 Nov 2001, Harald von Fellenberg - Sun Switzerland Zurich - Technology Strategy Office wrote:

> This said, I would like to re-raise the importance of non-ext2 file system
> support, notably ReiserFS. It has been pointed out before, by Stephen Smalley,
> that this should in principle be easy to integrate (the per-node sec context
> needs to be stored in a file rather than in an unused field of the on-disk inode
> structure). However, I am not aware of anyone tackling this implementation.

Only the original SELinux prototype was limited to the ext2 filesystem, due to the use of a spare field in the on-disk ext2 inode to store the persistent security identifier (PSID). When we transitioned to LSM, we extended the persistent label mapping to maintain the inode-to-PSID mapping as a regular file because LSM does not provide filesystem-specific hooks. Hence, the LSM-based SELinux prototype should be able to use ReiserFS, although we haven't tried it.

--
Stephen D. Smalley, NAI Labs
ssmalley@nai.com





--
You have received this message because you are subscribed to the selinux list.
If you no longer wish to subscribe, send mail to majordomo@tycho.nsa.gov with
the words "unsubscribe selinux" without quotes as the message.
Received on Mon 19 Nov 2001 - 10:06:26 EST

This archive was generated by hypermail 2.2.0 on Wed 11 Jun 2008 - 08:10:26 EDT