login
Login
/
Register
Search
Forums
News
Blogs
Features
Site
Home
»
Mailing list archives
»
linux-kernel
»
2007
»
October
»
8
Re: [PATCH] Version 3 (2.6.23-rc8) Smack: Simplified Mandatory Access Control Kernel
view
thread
!MAILaRCHIVE_VOTE_RePLACE
Previous message: [
thread
] [
date
] [
author
]
Next message: [thread] [
date
] [
author
]
[view in full thread]
From:
Serge E. Hallyn <serue@...>
To: Eric W. Biederman <ebiederm@...>
Cc: <casey@...>, Stephen Smalley <sds@...>, Kyle Moffett <mrmacman_g4@...>, Linus Torvalds <torvalds@...>, Bill Davidsen <davidsen@...>, James Morris <jmorris@...>, Andrew Morton <akpm@...>, <linux-security-module@...>, <linux-kernel@...>, Serge E. Hallyn <serge@...>
Subject:
Re: [PATCH] Version 3 (2.6.23-rc8) Smack: Simplified Mandatory Access Control Kernel
Date: Monday, October 8, 2007 - 2:53 pm
Quoting Eric W. Biederman (
ebiederm@xmission.com
):
quoted text
> Casey Schaufler <casey@schaufler-ca.com> writes: > > > --- "Eric W. Biederman" <ebiederm@xmission.com> wrote: > > > > > >> Likely. Until we have a generalized LSM interface with 1000 config > >> options like netfilter I don't expect we will have grounds to talk > >> or agree to a common user space interface. Although I could be > >> wrong. > > > > Gulp. I know that many of you are granularity advocates, but I > > have to say that security derived by tweeking 1000 knobs so that > > they are all just right seems a little far fetched to me. I see > > it as poopooing the 3rd and most important part of the reference > > monitor concept, "small enough to analyze". Sure, you can analyse > > the 1000 individual checks, but you'll never be able to describe > > the system behavior as a whole. > > Agreed. I wasn't thinking 1000 individual checks but 1000 different > capabilities, could be either checks or actions, basically fundamental > different capabilities. Things like CIPSO, or the ability to store a > security label on a file. I would not expect most security policies > to use most of them. Neither do I expect Orange book security to > necessarily be what people want to achieve with the LSM. But I > haven't looked at it enough detail to know how things should be > factored, in this case I was simply extrapolating from the iptables > experience where we do have a very large number of options. > > The real point being is that I would be surprised if we could come > to an agreement of a common user space API when we can't agree on how > to compile all of the security modules into the kernel and have them > play nice with each other. > > Assuming we can achieve security modules playing nice with each other > using a mechanism similar to iptables, then what needs to be evaluated > is the specific table configuration we are using on the system, not > the full general set of possibilities. Further I expect that for the > truly security paranoid we want the option to disable further table > changes after the tables have been configured. > > On another side personally I don't see where the idea comes from that > you can describe system behavior as a whole without analyzing the > entire kernel. Has there been work on a sparse like tool that I'm > not aware of to ensure the we always perform the appropriate security > checks on the user/kernel interface boundary?
Yup, see the top of
http://www.research.ibm.com/vali/
Pretty cool work that really should be continued. -serge -
unsubscribe notice
To unsubscribe from this list: send the line "unsubscribe linux-kernel" in the body of a message to
majordomo@vger.kernel.org
More majordomo info at
http://vger.kernel.org/majordomo-info.html
Please read the FAQ at
http://www.tux.org/lkml/
Previous message: [
thread
] [
date
] [
author
]
Next message: [thread] [
date
] [
author
]
Messages in current thread:
[PATCH] Version 3 (2.6.23-rc8) Smack: Simplified Mandatory A...
, Casey Schaufler
, (Sat Sep 29, 8:20 pm)
Re: [PATCH] Version 3 (2.6.23-rc8) Smack: Simplified Mandato...
, Serge E. Hallyn
, (Sun Sep 30, 11:47 pm)
Re: [PATCH] Version 3 (2.6.23-rc8) Smack: Simplified Mandato...
, Casey Schaufler
, (Mon Oct 1, 12:15 am)
Re: [PATCH] Version 3 (2.6.23-rc8) Smack: Simplified Mandato...
, Andrew Morton
, (Sun Sep 30, 4:16 am)
Re: [PATCH] Version 3 (2.6.23-rc8) Smack: Simplified Mandato...
, Jan Engelhardt
, (Mon Oct 1, 4:49 pm)
Re: [PATCH] Version 3 (2.6.23-rc8) Smack: Simplified Mandato...
, James Morris
, (Mon Oct 1, 7:33 am)
Re: [PATCH] Version 3 (2.6.23-rc8) Smack: Simplified Mandato...
, Casey Schaufler
, (Mon Oct 1, 11:38 am)
Re: [PATCH] Version 3 (2.6.23-rc8) Smack: Simplified Mandato...
, Linus Torvalds
, (Mon Oct 1, 11:07 am)
Re: [PATCH] Version 3 (2.6.23-rc8) Smack: Simplified Mandato...
, Stephen Smalley
, (Mon Oct 1, 11:40 am)
Re: [PATCH] Version 3 (2.6.23-rc8) Smack: Simplified Mandato...
, Theodore Tso
, (Mon Oct 1, 3:00 pm)
Re: [PATCH] Version 3 (2.6.23-rc8) Smack: Simplified Mandato...
, Casey Schaufler
, (Mon Oct 1, 12:39 pm)
Re: [PATCH] Version 3 (2.6.23-rc8) Smack: Simplified Mandato...
, Linus Torvalds
, (Mon Oct 1, 12:04 pm)
Re: [PATCH] Version 3 (2.6.23-rc8) Smack: Simplified Mandato...
, Bill Davidsen
, (Tue Oct 2, 5:02 pm)
Re: [PATCH] Version 3 (2.6.23-rc8) Smack: Simplified Mandato...
, Alan Cox
, (Tue Oct 2, 8:10 pm)
Re: [PATCH] Version 3 (2.6.23-rc8) Smack: Simplified Mandato...
, Linus Torvalds
, (Tue Oct 2, 8:18 pm)
Re: [PATCH] Version 3 (2.6.23-rc8) Smack: Simplified Mandato...
, Linus Torvalds
, (Tue Oct 2, 5:20 pm)
Re: [PATCH] Version 3 (2.6.23-rc8) Smack: Simplified Mandato...
, Bill Davidsen
, (Tue Oct 2, 11:54 pm)
Re: [PATCH] Version 3 (2.6.23-rc8) Smack: Simplified Mandato...
, Linus Torvalds
, (Wed Oct 3, 12:52 am)
Re: [PATCH] Version 3 (2.6.23-rc8) Smack: Simplified Mandato...
, Eric W. Biederman
, (Thu Oct 4, 9:44 pm)
Re: [PATCH] Version 3 (2.6.23-rc8) Smack: Simplified Mandato...
, Kyle Moffett
, (Thu Oct 4, 11:04 pm)
Re: [PATCH] Version 3 (2.6.23-rc8) Smack: Simplified Mandato...
, Bill Davidsen
, (Sat Oct 6, 3:14 pm)
Re: [PATCH] Version 3 (2.6.23-rc8) Smack: Simplified Mandato...
, Eric W. Biederman
, (Fri Oct 5, 12:45 am)
Re: [PATCH] Version 3 (2.6.23-rc8) Smack: Simplified Mandato...
, Serge E. Hallyn
, (Mon Oct 8, 12:06 pm)
Re: [PATCH] Version 3 (2.6.23-rc8) Smack: Simplified Mandato...
, Eric W. Biederman
, (Mon Oct 8, 1:20 pm)
Re: [PATCH] Version 3 (2.6.23-rc8) Smack: Simplified Mandato...
, Casey Schaufler
, (Mon Oct 8, 4:25 pm)
Re: [PATCH] Version 3 (2.6.23-rc8) Smack: Simplified Mandato...
, Eric W. Biederman
, (Mon Oct 8, 4:57 pm)
Re: [PATCH] Version 3 (2.6.23-rc8) Smack: Simplified Mandato...
, Serge E. Hallyn
, (Mon Oct 8, 2:00 pm)
Re: [PATCH] Version 3 (2.6.23-rc8) Smack: Simplified Mandato...
, Kazuki Omo(Company)
, (Tue Oct 30, 12:01 am)
Re: [PATCH] Version 3 (2.6.23-rc8) Smack: Simplified Mandato...
, Casey Schaufler
, (Tue Oct 30, 11:07 am)
Re: [PATCH] Version 3 (2.6.23-rc8) Smack: Simplified Mandato...
, Eric W. Biederman
, (Mon Oct 8, 3:50 pm)
Re: [PATCH] Version 3 (2.6.23-rc8) Smack: Simplified Mandato...
, Crispin Cowan
, (Mon Oct 8, 5:51 pm)
Re: [PATCH] Version 3 (2.6.23-rc8) Smack: Simplified Mandato...
, Alan Cox
, (Mon Oct 8, 5:20 pm)
Re: [PATCH] Version 3 (2.6.23-rc8) Smack: Simplified Mandato...
, Eric W. Biederman
, (Wed Oct 10, 9:48 am)
Re: [PATCH] Version 3 (2.6.23-rc8) Smack: Simplified Mandato...
, Stephen Smalley
, (Wed Oct 10, 11:45 am)
Re: [PATCH] Version 3 (2.6.23-rc8) Smack: Simplified Mandato...
, Casey Schaufler
, (Wed Oct 10, 1:57 pm)
Re: [PATCH] Version 3 (2.6.23-rc8) Smack: Simplified Mandato...
, Kyle Moffett
, (Thu Oct 11, 6:46 am)
Re: [PATCH] Version 3 (2.6.23-rc8) Smack: Simplified Mandato...
, Casey Schaufler
, (Thu Oct 11, 11:41 am)
Re: [PATCH] Version 3 (2.6.23-rc8) Smack: Simplified Mandato...
, Kyle Moffett
, (Thu Oct 11, 2:53 pm)
Re: [PATCH] Version 3 (2.6.23-rc8) Smack: Simplified Mandato...
, Alan Cox
, (Thu Oct 11, 4:09 pm)
Re: [PATCH] Version 3 (2.6.23-rc8) Smack: Simplified Mandato...
, Casey Schaufler
, (Mon Oct 8, 4:39 pm)
Re: [PATCH] Version 3 (2.6.23-rc8) Smack: Simplified Mandato...
, Eric W. Biederman
, (Mon Oct 8, 5:02 pm)
Re: [PATCH] Version 3 (2.6.23-rc8) Smack: Simplified Mandato...
, Eric W. Biederman
, (Mon Oct 8, 3:29 pm)
Re: [PATCH] Version 3 (2.6.23-rc8) Smack: Simplified Mandato...
, Kyle Moffett
, (Fri Oct 5, 1:48 am)
Re: [PATCH] Version 3 (2.6.23-rc8) Smack: Simplified Mandato...
, Casey Schaufler
, (Fri Oct 5, 12:27 pm)
Re: [PATCH] Version 3 (2.6.23-rc8) Smack: Simplified Mandato...
, Serge E. Hallyn
, (Mon Oct 8, 12:18 pm)
Re: [PATCH] Version 3 (2.6.23-rc8) Smack: Simplified Mandato...
, Bill Davidsen
, (Mon Oct 8, 7:24 pm)
Re: [PATCH] Version 3 (2.6.23-rc8) Smack: Simplified Mandato...
, Casey Schaufler
, (Mon Oct 8, 1:31 pm)
Re: [PATCH] Version 3 (2.6.23-rc8) Smack: Simplified Mandato...
, Stephen Smalley
, (Tue Oct 9, 9:52 am)
Re: [PATCH] Version 3 (2.6.23-rc8) Smack: Simplified Mandato...
, Casey Schaufler
, (Tue Oct 9, 12:02 pm)
Re: [PATCH] Version 3 (2.6.23-rc8) Smack: Simplified Mandato...
, Stephen Smalley
, (Fri Oct 5, 2:42 pm)
Re: [PATCH] Version 3 (2.6.23-rc8) Smack: Simplified Mandato...
, Eric W. Biederman
, (Fri Oct 5, 4:11 pm)
Re: [PATCH] Version 3 (2.6.23-rc8) Smack: Simplified Mandato...
, Casey Schaufler
, (Mon Oct 8, 1:50 pm)
Re: [PATCH] Version 3 (2.6.23-rc8) Smack: Simplified Mandato...
, Eric W. Biederman
, (Mon Oct 8, 2:47 pm)
Re: [PATCH] Version 3 (2.6.23-rc8) Smack: Simplified Mandato...
, Casey Schaufler
, (Mon Oct 8, 5:05 pm)
Re: [PATCH] Version 3 (2.6.23-rc8) Smack: Simplified Mandato...
, Serge E. Hallyn
, (Mon Oct 8, 2:53 pm)
Re: [PATCH] Version 3 (2.6.23-rc8) Smack: Simplified Mandato...
, Casey Schaufler
, (Fri Oct 5, 4:08 pm)
Re: [PATCH] Version 3 (2.6.23-rc8) Smack: Simplified Mandato...
, Linus Torvalds
, (Tue Oct 2, 7:25 pm)
Re: [PATCH] Version 3 (2.6.23-rc8) Smack: Simplified Mandato...
, Crispin Cowan
, (Wed Oct 3, 1:32 am)
Re: [PATCH] Version 3 (2.6.23-rc8) Smack: Simplified Mandato...
, Alan Cox
, (Tue Oct 2, 8:12 pm)
Re: [PATCH] Version 3 (2.6.23-rc8) Smack: Simplified Mandato...
, Derek Fawcus
, (Thu Oct 4, 6:56 pm)
Re: [PATCH] Version 3 (2.6.23-rc8) Smack: Simplified Mandato...
, Chuck Ebbert
, (Thu Oct 4, 7:18 pm)
Re: [PATCH] Version 3 (2.6.23-rc8) Smack: Simplified Mandato...
, Derek Fawcus
, (Thu Oct 4, 7:44 pm)
Re: [PATCH] Version 3 (2.6.23-rc8) Smack: Simplified Mandato...
, Olivier Galibert
, (Mon Oct 1, 1:54 pm)
Re: [PATCH] Version 3 (2.6.23-rc8) Smack: Simplified Mandato...
, Paul Moore
, (Sun Sep 30, 4:30 pm)
Re: [PATCH] Version 3 (2.6.23-rc8) Smack: Simplified Mandato...
, Casey Schaufler
, (Sun Sep 30, 1:02 pm)
Re: [PATCH] Version 3 (2.6.23-rc8) Smack: Simplified Mandato...
, Andi Kleen
, (Sun Sep 30, 4:42 am)
Re: [PATCH] Version 3 (2.6.23-rc8) Smack: Simplified Mandato...
, Casey Schaufler
, (Sun Sep 30, 1:14 pm)
Re: [PATCH] Version 3 (2.6.23-rc8) Smack: Simplified Mandato...
, Andi Kleen
, (Sun Sep 30, 1:34 pm)
Re: [PATCH] Version 3 (2.6.23-rc8) Smack: Simplified Mandato...
,
, (Sun Sep 30, 7:24 pm)
Re: [PATCH] Version 3 (2.6.23-rc8) Smack: Simplified Mandato...
, Joshua Brindle
, (Sun Sep 30, 1:29 pm)
Re: [PATCH] Version 3 (2.6.23-rc8) Smack: Simplified Mandato...
, Andi Kleen
, (Sun Sep 30, 1:39 pm)
Re: [PATCH] Version 3 (2.6.23-rc8) Smack: Simplified Mandato...
, Theodore Tso
, (Sun Sep 30, 3:07 pm)
Re: [PATCH] Version 3 (2.6.23-rc8) Smack: Simplified Mandato...
, Paul Moore
, (Sun Sep 30, 4:18 pm)
Re: [PATCH] Version 3 (2.6.23-rc8) Smack: Simplified Mandato...
, Andi Kleen
, (Sun Sep 30, 4:05 pm)
Re: [PATCH] Version 3 (2.6.23-rc8) Smack: Simplified Mandato...
, Casey Schaufler
, (Mon Oct 1, 4:28 pm)
Re: [PATCH] Version 3 (2.6.23-rc8) Smack: Simplified Mandato...
, Theodore Tso
, (Sun Sep 30, 4:22 pm)
Re: [PATCH] Version 3 (2.6.23-rc8) Smack: Simplified Mandato...
, Christoph Hellwig
, (Sun Sep 30, 5:53 am)
Re: [PATCH] Version 3 (2.6.23-rc8) Smack: Simplified Mandato...
, Thomas Bleher
, (Tue Oct 2, 4:36 am)
Re: [PATCH] Version 3 (2.6.23-rc8) Smack: Simplified Mandato...
, Casey Schaufler
, (Sun Sep 30, 1:19 pm)
Navigation
Create content
Mailing list archives
Recent posts
Popular discussions
linux-kernel
:
Joe Perches
[PATCH 143/148] include/asm-x86/vm86.h: checkpatch cleanups - formatting only
Linus Torvalds
Re: Back to the future.
Greg Kroah-Hartman
[PATCH 004/196] Chinese: add translation of SubmittingPatches
Trent Piepho
[PATCH] [POWERPC] Improve (in|out)_beXX() asm code
git
:
openbsd-misc
:
linux-netdev
:
David Miller
Re: [PATCH] pkt_sched: Destroy gen estimators under rtnl_lock().
Gerrit Renker
[PATCH 15/37] dccp: Set per-connection CCIDs via socket options
David Miller
[GIT]: Networking
Linus Torvalds
Re: iptables very slow after commit 784544739a25c30637397ace5489eeb6e15d7d49
Colocation donated by:
Who's online
There are currently
3 users
and
719 guests
online.
Online users
patentstransla
protectedtrust5
motiol45
Syndicate