Skip site navigation (1)Skip section navigation (2)
Date:      Wed, 19 Jul 2017 11:26:18 +1000
From:      Dewayne Geraghty <dewayne.geraghty@heuristicsystems.com.au>
To:        Martin Beran <martin@mber.cz>, freebsd-hackers@freebsd.org
Subject:   Re: mac_sofi: a proof of concept MAC module
Message-ID:  <5f10fbd6-f8aa-0e47-0861-9bfebff0ca74@heuristicsystems.com.au>
In-Reply-To: <c12f4b21-ca87-c958-349d-475d51d61d88@mber.cz>
References:  <c12f4b21-ca87-c958-349d-475d51d61d88@mber.cz>

next in thread | previous in thread | raw e-mail | index | archive | help
Martin,
Would it be possible to expand on how SOFI is better/different to MAC
lomac?  As it seems that the testing program is the differentiator?

Aside: Also you may not be aware that system namespace extended
attributes do not function within a jail, though this is the same as the
rest of MAC.  I'm told that SELinux uses "security" and others use
"trusted" namespaces, perhaps for some future FreeBSD...?

Regards, Dewayne.



Want to link to this message? Use this URL: <https://mail-archive.FreeBSD.org/cgi/mid.cgi?5f10fbd6-f8aa-0e47-0861-9bfebff0ca74>