Re: [PATCH] LSM: MntRestrict blocks mounts on symlink targets

2013-10-04 Thread David Quigley
Why is this an LSM and not something further up in the VFS? Why not make a sysctl for this and place it further up in the VFS? Has it already been rejected from there? If so why not include it in the things covered by Yama? From a code perspective I can't find anything wrong code wise but it se

Re: linux-next: manual merge of the selinux tree with Linus' tree

2013-07-25 Thread David Quigley
and can carry the fix as necessary (no action > is required). > > P.S. Unusually, that commit from Linus' tree has no Signed-off-by from > its purported author (David Quigley). > -- > Cheers, > Stephen Rothwells...@canb.auug.org.au > diff --cc secu