--- Thomas Fricaccia <thomas_fricacci@yahoo.com> wrote:
I make no claims to worthyness, strongly deny being serious,
and challenge you to demonstrate my good repute.
Nope. I remain carefully neutral regarding the static/dynamic LSM
issue. I was involved with the LSM when SELinux was still known as
the Flask port and my development group proposed the first
implementation, featuring authoritative hooks. Believe me, this
is nothing compared to what we went through as a community then.
The thing that killed authoritative hooks and that could kill LSM
is the notion (which I refuse to take a side on) that out of tree
facilities can use it to avoid the stated intent of the GPL.
I think the primary parties have gotten to the point where they
just call out the arguments by number we've been over them so many
times.
It goes way beyond frowned upon. The first use proposed for LSM was
an audit implementation and that was throughly shredded. Additional
restrictions on accesses only.
Which is pure feldercarb.
That argument makes Linus mad.
The in-tree vs out-of-tree discussion is independent of LSM.
Casey Schaufler
casey@schaufler-ca.com
-