Re: LSM conversion to static interface

!MAILaRCHIVE_VOTE_RePLACE
Previous message: [thread] [date] [author]
Next message: [thread] [date] [author]
To: Thomas Fricaccia <thomas_fricacci@...>, <linux-kernel@...>
Cc: Linus Torvalds <torvalds@...>
Date: Wednesday, October 17, 2007 - 10:03 pm

--- Thomas Fricaccia <thomas_fricacci@yahoo.com> wrote:


I make no claims to worthyness, strongly deny being serious,
and challenge you to demonstrate my good repute.


Nope. I remain carefully neutral regarding the static/dynamic LSM
issue. I was involved with the LSM when SELinux was still known as
the Flask port and my development group proposed the first
implementation, featuring authoritative hooks. Believe me, this
is nothing compared to what we went through as a community then.


The thing that killed authoritative hooks and that could kill LSM
is the notion (which I refuse to take a side on) that out of tree
facilities can use it to avoid the stated intent of the GPL.


I think the primary parties have gotten to the point where they
just call out the arguments by number we've been over them so many
times.


It goes way beyond frowned upon. The first use proposed for LSM was
an audit implementation and that was throughly shredded. Additional
restrictions on accesses only.


Which is pure feldercarb.


That argument makes Linus mad.


The in-tree vs out-of-tree discussion is independent of LSM.


Casey Schaufler
casey@schaufler-ca.com
-
Previous message: [thread] [date] [author]
Next message: [thread] [date] [author]

Messages in current thread:
LSM conversion to static interface, Thomas Fricaccia, (Wed Oct 17, 9:34 pm)
Re: LSM conversion to static interface, Arjan van de Ven, (Wed Oct 17, 11:06 pm)
Re: LSM conversion to static interface, Casey Schaufler, (Wed Oct 17, 10:03 pm)
Re: LSM conversion to static interface, Linus Torvalds, (Wed Oct 17, 10:21 pm)