Heh, it's a valid question. I like per-module attributes, but I don't
think they are as nice for userland tools. I don't acutally like
encoding namesapce into the attribute value, but I'm not sure the
alternative is much different/better.
> Would it make sense to have a single "backup/restore security label" tool
> that is distributed alongside LSM rather than relying on each module writer
> developing their own.
You mean to ensure that labels are accumulated rather than replaced?
Could be useful I suppose.
thanks,
-chris
-- Linux Security Modules http://lsm.immunix.org http://lsm.bkbits.net - To unsubscribe from this list: send the line "unsubscribe linux-kernel" in the body of a message to majordomo@vger.kernel.org More majordomo info at http://vger.kernel.org/majordomo-info.html Please read the FAQ at http://www.tux.org/lkml/