On Thu, 25 Oct 2007 09:04:57 -0700 "Ray Lee" <ray-lk@madrabbit.org> wrote:I absolutely agree it's a layer game. HOWEVER, even in a layer game we need to have each layer to be reasonably solid and not just fake security ("snakeoil"). So while I think it is entirely fair to judge a piece of software against what it intends/claims to do, because other pieces in the layer game will depend on it to function reasonably well. So most of the LSM fist-fights have been about disagreement of the intent; and some about code not living up to its own intend, all mixed up. Arguing about the intent is less productive imo (as long as it's at least somewhat reasonable, intend like "I want to add rootkits" doesn't count obviously), paying attention to check if the code lives up to its stated intent/purpose on the other hand is immensely useful and needed; for a given implementation it may mean reducing the scope of the intent if the implementation just doesn't go as wide as originally thought, or fixing some issues in the implementation to live up to the intent. -
| Jeff Garzik | Re: Wasting our Freedom |
| Chuck Ebbert | Why do so many machines need "noapic"? |
| Mathieu Desnoyers | [RFC patch 08/18] cnt32_to_63 should use smp_rmb() |
| Richard Hughes | Add INPUT support to toshiba_acpi |
git: | |
| Jan | [PATCH/RFC] Allow writing loose objects that are corrupted in a pack file |
| Elijah Newren | Trying to use git-filter-branch to compress history by removing large, obsolete bi... |
| Thomas Koch | is gitosis secure? |
| Matthieu Moy | git push to a non-bare repository |
| frantisek holop | booting openbsd on eee without cd-rom |
| GVG GVG | ssh_exchange_identification: Connection closed by remote host |
| Otto Moerbeek | Re: identifying sparse files and get ride of them trick available? |
| Renaud Allard | very weak bridge performance |
| Linux Kernel Mailing List | [ALSA] hda: Added new IDT codec family |
| Linux Kernel Mailing List | usb-storage: clean up unusual_devs.h |
| Linux Kernel Mailing List | USB: Enhance usage of pm_message_t |
| Linux Kernel Mailing List | resource: allow MMIO exclusivity for device drivers |
