SELinux: Improve read/write performance
authorYuichi Nakamura <ynakam@hitachisoft.jp>
Fri, 14 Sep 2007 00:27:07 +0000 (09:27 +0900)
committerJames Morris <jmorris@namei.org>
Tue, 16 Oct 2007 22:59:31 +0000 (08:59 +1000)
It reduces the selinux overhead on read/write by only revalidating
permissions in selinux_file_permission if the task or inode labels have
changed or the policy has changed since the open-time check.  A new LSM
hook, security_dentry_open, is added to capture the necessary state at open
time to allow this optimization.

(see http://marc.info/?l=selinux&m=118972995207740&w=2)

Signed-off-by: Yuichi Nakamura<ynakam@hitachisoft.jp>
Acked-by: Stephen Smalley <sds@tycho.nsa.gov>
Signed-off-by: James Morris <jmorris@namei.org>

No differences found