On Thu, 25 Oct 2007 09:04:57 -0700 "Ray Lee" <ray-lk@madrabbit.org> wrote:I absolutely agree it's a layer game. HOWEVER, even in a layer game we need to have each layer to be reasonably solid and not just fake security ("snakeoil"). So while I think it is entirely fair to judge a piece of software against what it intends/claims to do, because other pieces in the layer game will depend on it to function reasonably well. So most of the LSM fist-fights have been about disagreement of the intent; and some about code not living up to its own intend, all mixed up. Arguing about the intent is less productive imo (as long as it's at least somewhat reasonable, intend like "I want to add rootkits" doesn't count obviously), paying attention to check if the code lives up to its stated intent/purpose on the other hand is immensely useful and needed; for a given implementation it may mean reducing the scope of the intent if the implementation just doesn't go as wide as originally thought, or fixing some issues in the implementation to live up to the intent. -
| Adrian Bunk | Re: Linux 2.6.21 |
| Linus Torvalds | Linux 2.6.21-rc2 |
| WANG Cong | [-mm Patch] UML: fix a building error |
| Roland McGrath | Re: [PATCH 0/5] ftrace: to kill a daemon |
git: | |
| Natalie Protasevich | [BUG] New Kernel Bugs |
| David Miller | Re: [PATCH] pkt_sched: Destroy gen estimators under rtnl_lock(). |
| Patrick McHardy | Re: [PATCH] netfilter: use per-cpu spinlock rather than RCU (v3) |
| Gerrit Renker | [PATCH 27/37] dccp: Integration of dynamic feature activation - part 2 (server side) |
| Theodore Ts'o | Re: cc1 fails silently |
| Michael Nolan | Power routines on notebook cause kernel panic |
| Marc Peters | v 0.11 boot disk problem |
| Dave `geek' Gymer | WARNING (was Re: New afio release) |
