Re: Upstream first policy

From: Ulrich Drepper
Date: Tue Mar 09 2010 - 09:59:15 EST


On Tue, Mar 9, 2010 at 00:46, Dave Airlie <airlied@xxxxxxxxx> wrote:
> selinux relabels are the new fsck.
>
> maybe we need selinux3 or chunk-selinux.

Once the fanotify stuff is in (or however it'll be called) the new
relabel process could temporarily install itself to intercept all
filesystem operations and fix up files on demand while going along
it's normal operation in the background. No reason to stall the
system completely.

If this is the biggest complaint then you should be supportive of the approach.
--
To unsubscribe from this list: send the line "unsubscribe linux-kernel" in
the body of a message to majordomo@xxxxxxxxxxxxxxx
More majordomo info at http://vger.kernel.org/majordomo-info.html
Please read the FAQ at http://www.tux.org/lkml/