Date: Wed, 19 Jul 2017 11:26:18 +1000 From: Dewayne Geraghty <dewayne.geraghty@heuristicsystems.com.au> To: Martin Beran <martin@mber.cz>, freebsd-hackers@freebsd.org Subject: Re: mac_sofi: a proof of concept MAC module Message-ID: <5f10fbd6-f8aa-0e47-0861-9bfebff0ca74@heuristicsystems.com.au> In-Reply-To: <c12f4b21-ca87-c958-349d-475d51d61d88@mber.cz> References: <c12f4b21-ca87-c958-349d-475d51d61d88@mber.cz>
next in thread | previous in thread | raw e-mail | index | archive | help
Martin, Would it be possible to expand on how SOFI is better/different to MAC lomac? As it seems that the testing program is the differentiator? Aside: Also you may not be aware that system namespace extended attributes do not function within a jail, though this is the same as the rest of MAC. I'm told that SELinux uses "security" and others use "trusted" namespaces, perhaps for some future FreeBSD...? Regards, Dewayne.
Want to link to this message? Use this URL: <https://mail-archive.FreeBSD.org/cgi/mid.cgi?5f10fbd6-f8aa-0e47-0861-9bfebff0ca74>