Re: [PATCH v12] xsm: refactor flask sid alloc and domain check

2022-08-17 Thread Jason Andryuk
On Wed, Aug 17, 2022 at 10:16 AM Daniel P. Smith wrote: > > On 8/16/22 13:43, Jason Andryuk wrote: > > Hi, > > > > I think you should change the title to "xsm/flask: Boot-time labeling > > for multiple domains". Refactor implies no functional change, and > > this is a functional change. With thi

Re: [PATCH v12] xsm: refactor flask sid alloc and domain check

2022-08-17 Thread Daniel P. Smith
On 8/16/22 13:43, Jason Andryuk wrote: Hi, I think you should change the title to "xsm/flask: Boot-time labeling for multiple domains". Refactor implies no functional change, and this is a functional change. With this, I think the commit message should be re-written to focus on the "why" of th

Re: [PATCH v12] xsm: refactor flask sid alloc and domain check

2022-08-16 Thread Jason Andryuk
Hi, I think you should change the title to "xsm/flask: Boot-time labeling for multiple domains". Refactor implies no functional change, and this is a functional change. With this, I think the commit message should be re-written to focus on the "why" of the new labeling policy. On Tue, Aug 9, 20

[PATCH v12] xsm: refactor flask sid alloc and domain check

2022-08-09 Thread Daniel P. Smith
The function flask_domain_alloc_security() allocates the security context and assigns an initial SID for the domain under construction. When it came to SID assignment of the initial domain, flask_domain_alloc_security() would assign unlabeled_t. Then in flask_domain_create() it would be switched to