Stephen Smalley <sds@tycho.nsa.gov> writes:Yes. Simple isolation is a different and simpler problem that can be solved with the LSM hooks today. I brought it up for the contrast in what the LSM hooks can be useful for. Hopefully allowing the LSM hooks to be perceived as something other then just hacks for selinux. Using a security module for isolation is currently uninteresting because it would preclude use of a security module like selinux or smack, because we can have at most one security module at a time loaded. I have seen several other places where a custom LSM would have been a good solution but because we don't allow composition solving a little problem with the LSm is not interesting enough to allow the code to be merged. So I see the current structure of the LSM hooks as hindering development. Exactly refactoring security modules into small simple reusable chunks to allow reuse. It might look something like selinux chains or it might not. Inherently it needs to expose what you can do at the existing hook points, and it needs to allow usage by different modules that are compiled in at the same time. It is certainly the case that you would not need to use all of the existing hooks to get something done. Likely. Until we have a generalized LSM interface with 1000 config options like netfilter I don't expect we will have grounds to talk or agree to a common user space interface. Although I could be wrong. Eric -
| Vladislav Bolkhovitin | Re: Integration of SCST in the mainstream Linux kernel |
| Linus Torvalds | Re: 2.6.25-git2: BUG: unable to handle kernel paging request at ffffffffffffffff |
| S.Çağlar | Rescheduling interrupts |
| Andi Kleen | Re: [patch] Add basic sanity checks to the syscall execution patch |
git: | |
| Jon Smirl | Re: Figured out how to get Mozilla into git |
| Matt McCutchen | Multiple checkouts of the same repository |
| Willy Tarreau | Multiple working trees with GIT ? |
| Linus Torvalds | Re: git + ssh + key authentication feature-request |
| Richard Stallman | Real men don't attack straw men |
| Adam Getchell | Re: About Xen: maybe a reiterative question but .. |
| Girish Venkatachalam | Thinkpad t61 OpenBSD support? |
| carlopmart | About Xen: maybe a reiterative question but .. |
| Jeff Kirsher | [PATCH 1/3] e1000e: add support for the 82567LM-4 device |
| slavon | Re: e1000_clean_tx_irq: Detected Tx Unit Hang - it's bug? |
| Hugh Dickins | Re: [bug?] tg3: Failed to load firmware "tigon/tg3_tso.bin" |
| Eliezer Tamir | Re: [PATCH][BNX2X] added register coments |
