On Fri, Jun 22, 2007 at 10:23:03AM -0400, James Morris wrote:
It is definitely useful to clearly understand the intended AA use cases
during the merge.
I'm sure people there will have a different versions of events. The
one part that was discussed was if pathname based security was
useful, and a number of the people in the room (outside of
novell) said it was. Now, it could be that nobody wanted to argue
anymore, since most opinions had come out on one list or another by
then.
But as someone who doesn't use either SElinux or AA, I really hope
we can get past the part of the debate where:
while(1)
AA) we think we're making users happy with pathname security
SELINUX) pathname security sucks
So, yes Greg got it started and Lars is a well known trouble maker, and
I completely understand if you want to say no thank you to an selinux
based AA ;) The models are different and it shouldn't be a requirement
that they try to use the same underlying mechanisms.
-chris
-