On Thu, 21 Jun 2007, Joshua Brindle wrote:correct, but we are talking about what a confined process can get to without assistance from an unconfined process. AA can be extended to cover these things in the future. remember 'release early release often'? how about 'perfect is the enemy of good enoug'? at this point they're trying to get the initial implementation in so that people can start takeing advantage of it. As a side effect the cost of maintaining it will decrease, and they can put effort into planning future enhancements. besides, as far as the network communication goes, doesn't netfilter now have a way to make rules for specific processes? if they don't then it could be added, but the details of the implementation would probably be very different from the current AA file controls. how does delaying the acceptance of the current implementation encourage the additional features being added? but to answer your two comments. how does mozilla access your mail over the network without first capturing your password from somewhere? as far as IPC goes, unix sockets are unavailable (AA as-is will control them), so you must be talking about signals or shared memory as the IPC mechanisms that mozilla would use to access your mail. please explain to me what mail client you are useing that exposes your mail via these mechinsms. David Lang - To unsubscribe from this list: send the line "unsubscribe linux-security-module" in the body of a message to majordomo@vger.kernel.org More majordomo info at http://vger.kernel.org/majordomo-info.html
| David Miller | [GIT]: Networking |
| Fred . | Please add ZFS support (from GPL sources) |
| Greg KH | [patch 00/47] 2.6.25-stable review |
| Davide Libenzi | Re: [patch 7/8] fdmap v2 - implement sys_socket2 |
git: | |
| Jakub Narebski | [RFC] Git User's Survey 2008 |
| Lars Hjemli | [PATCH] git-merge: add option --no-ff |
| Johannes Schindelin | Re: [PATCH 3/4] Add a function for get the parents of a commit |
| Sebastian Schuberth | git on Cygwin: Not a valid object name HEAD |
| GVG GVG | ssh_exchange_identification: Connection closed by remote host |
| bofh | Re: Code signing in OpenBSD |
| Richard Stallman | Real men don't attack straw men |
| William Bloom | Re: site-to-site vpn 4.0 to cisco 3000 |
| Larry McVoy | Re: tcp bw in 2.6 |
| denys | NMI lockup, 2.6.26 release |
| Kok, Auke | Re: [E1000-devel] [PATCH 2/2] [e1000 VLAN] Disable vlan hw accel when promiscuous ... |
| David Miller | Re: 2.6.25-rc8: FTP transfer errors |
