login
Header Space

 
 

Re: LSM conversion to static interface

Score:
Previous message: [thread] [date] [author]
Next message: [thread] [date] [author]
To: Alan Cox <alan@...>
Cc: Thomas Fricaccia <thomas_fricacci@...>, <linux-kernel@...>, LSM ML <linux-security-module@...>, Linus Torvalds <torvalds@...>
Date: Monday, October 22, 2007 - 12:10 pm

Alan Cox wrote:
I agree that SarBox is not really the issue here. Partially related is
enterprise rules about what kernels one is allowed to load. More
generally, this change forces users who want to use a different LSM than
their vendor provides to recompile their kernel, where they did not have
to recompile before. It forces LSM module developers who want to modify
their LSM to reboot, where they didn't necessarily have to reboot before.

That is not a catastrophe, it is just tedious. It does not kill baby
seals, and it does not make Linux utterly useless. OTOH, I think it is
strictly negative: it takes away user choice in 2 dimensions, and adds
zero value. So apply it if you must to bake the kernel developer's lives
easier, but it really is a net loss in Linux kernel capability.

Crispin

-- 
Crispin Cowan, Ph.D.               http://crispincowan.com/~crispin/
	       Itanium. Vista. GPLv3. Complexity at work

-
Previous message: [thread] [date] [author]
Next message: [thread] [date] [author]

Messages in current thread:
Re: LSM conversion to static interface, Thomas Fricaccia, (Sun Oct 21, 10:24 pm)
Re: LSM conversion to static interface, Alan Cox, (Mon Oct 22, 6:07 am)
Re: LSM conversion to static interface, Crispin Cowan, (Mon Oct 22, 12:10 pm)
Re: LSM conversion to static interface, Alan Cox, (Mon Oct 22, 12:50 pm)
Re: LSM conversion to static interface, Greg KH, (Mon Oct 22, 12:56 pm)
Re: LSM conversion to static interface, Greg KH, (Sun Oct 21, 11:59 pm)
Re: LSM conversion to static interface, Geert Uytterhoeven, (Tue Oct 23, 12:52 pm)
Re: LSM conversion to static interface, Avi Kivity, (Mon Oct 22, 1:47 pm)
Re: LSM conversion to static interface, Adrian Bunk, (Tue Oct 23, 12:05 pm)
speck-geostationary