[Date Prev][Date Next]   [Thread Prev][Thread Next]   [Thread Index] [Date Index] [Author Index]

Re: [PATCH] LSPP audit enablement: storing selinux ocontext and scontext



On Mon, 26 Sep 2005 16:28:39 EDT, Steve Grubb said:

> 1500 - 1599 kernel LSPP events
> 1700 - 1799 kernel crypto events
> 1800 - 1999 future kernel use (maybe integrity labels and related events)
< and so on..>

Am I the only one who thinks "100 entries will be enough" sounds suspiciously
like "640K should be enough for anybody"?  Do we either have a way to
guarantee that it will be enough (go with pseudo-fractional entries
a la '1701 subtype 1, 2, 3, 1702 subtype 1..8, 1703 subtype 1..934, etc',
or a way to expand it, keeping in mind forward/backward combatibility issues)?

Attachment: pgp6yfcRZ7eHl.pgp
Description: PGP signature


[Date Prev][Date Next]   [Thread Prev][Thread Next]   [Thread Index] [Date Index] [Author Index]