Re: [Apparmor-dev] Re: AppArmor Security Goal

!MAILaRCHIVE_VOTE_RePLACE
Previous message: [thread] [date] [author]
Next message: [thread] [date] [author]
To: <rmeijer@...>, <apparmor-dev@...>
Cc: Crispin Cowan <crispin@...>, LSM ML <linux-security-module@...>, linux-kernel@vger.kernel.org <linux-kernel@...>, Arjan van de Ven <arjan@...>
Date: Tuesday, November 13, 2007 - 4:23 am

Re-sent with proper addressing ...

Rob Meijer wrote:
As far as I can tall, the transitive closure of permissions is precisely
authority.

It is deliberately unspecified in this document, because it is a matter
of policy. And this item that you've excerpted is just one of a list of
specific disclaimers that were put here in response to criticisms and
misunderstandings of AppArmor in the past.

Remember, the purpose of *this* document is to define the security goals
that AppArmor has to live up to. It is fine to use it as a jumping off
point for design ideas that some system might employ some day, or even
proposed enhancements to AppArmor itself, but don't over-burden the
"security goal" document, it needs to be short & comprehensible.

It counts as a surprising result, and so is specifically disclaimed. I
can tell it is surprising, because it surprised Andi Kleen :)

Crispin

-- 
Crispin Cowan, Ph.D.               http://crispincowan.com/~crispin
CEO, Mercenary Linux		   http://mercenarylinux.com/
	       Itanium. Vista. GPLv3. Complexity at work
-
Previous message: [thread] [date] [author]
Next message: [thread] [date] [author]

Messages in current thread:
Re: [Apparmor-dev] Re: AppArmor Security Goal, Crispin Cowan, (Tue Nov 13, 4:23 am)
Re: [Apparmor-dev] Re: AppArmor Security Goal, Peter Dolding, (Thu Nov 15, 6:58 pm)