Re: [PATCH 06b/26] Security: Make NFSD work with detached security

From: David Howells
Date: Thu Jan 17 2008 - 18:03:38 EST


David Howells <dhowells@xxxxxxxxxx> wrote:

> J. Bruce Fields <bfields@xxxxxxxxxxxx> wrote:
>
> > Just curious--why? Are get_kernel_security(), etc., particularly
> > expensive?
>
> It involves a kmalloc(). That means an extra possibility for an error. Plus
> it may allow you to cache the result of checking whether, say, SELinux
> security labels are allowed to be set when passed over NFS (if such is
> possible).

Apart from that, though, no, it's not particularly expensive.

David
--
To unsubscribe from this list: send the line "unsubscribe linux-kernel" in
the body of a message to majordomo@xxxxxxxxxxxxxxx
More majordomo info at http://vger.kernel.org/majordomo-info.html
Please read the FAQ at http://www.tux.org/lkml/