[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]

Re: [Xen-devel] [PATCH 10/17] flask: remove xen_flask_userlist operation


  • To: Doug Goldstein <cardoe@xxxxxxxxxx>, xen-devel@xxxxxxxxxxxxx
  • From: Daniel De Graaf <dgdegra@xxxxxxxxxxxxx>
  • Date: Mon, 20 Jun 2016 11:07:05 -0400
  • Delivery-date: Mon, 20 Jun 2016 15:07:15 +0000
  • Ironport-phdr: 9a23:3Gyr5xXrZWXTwYXyq1iMHJd5m57V8LGtZVwlr6E/grcLSJyIuqrYZh2At8tkgFKBZ4jH8fUM07OQ6PCxHz1dqsnQ+Fk5M7VyFDY9wf0MmAIhBMPXQWbaF9XNKxIAIcJZSVV+9Gu6O0UGUOz3ZlnVv2HgpWVKQka3CwN5K6zPF5LIiIzvjqbpq8yVMlgD22v1SIgxBSv1hD2ZjtMRj4pmJ/R54TryiVwMRd5rw3h1L0mYhRf265T41pdi9yNNp6BprJYYAu3HZaBwcZh0RHRjaTh0t4XXskzvShaArlQbVmkNjhdJBUCR5xjgUpD8miDzrOZ61W+ROsigCfgkVDLn46p1RRvAjCYcKyV/4GzRzMtqg/F1uhWk8jB2xY/ZZMm5ObJRZKrUc5tOSWVNU8lLXgRdE4i8aM0JFONHMuFG+dqu72ASpAezUFH/TNjkzSVF0zqshaA=
  • List-id: Xen developer discussion <xen-devel.lists.xen.org>

On 06/20/2016 10:35 AM, Doug Goldstein wrote:
On 6/20/16 9:04 AM, Daniel De Graaf wrote:
This operation has no known users, and is primarily useful when an MLS
policy is in use (which has never been shipped with Xen).  In addition,
the information it provides does not actually depend on hypervisor
state (only on the XSM policy), so an application that needs it could
compute the results without needing to involve the hypervisor.


So if I read this language correctly. Removing this does not affect
someone being able to build a MLS policy at a later date right?

Correct; that support is still there.  This hypercall was used to
compute a list of reachable security contexts for a given user, which
is trivial in a non-MLS policy but more complex when one is being
used.  This computation makes more sense on Linux (where creating
new contexts via "exec" is common) than on Xen (where normally a
domain cannot create another).

--
Daniel De Graaf
National Security Agency

_______________________________________________
Xen-devel mailing list
Xen-devel@xxxxxxxxxxxxx
http://lists.xen.org/xen-devel

 


Rackspace

Lists.xenproject.org is hosted with RackSpace, monitoring our
servers 24x7x365 and backed by RackSpace's Fanatical Support®.