Re: [Apparmor-dev] Re: AppArmor Security Goal

!MAILaRCHIVE_VOTE_RePLACE
Previous message: [thread] [date] [author]
Next message: [thread] [date] [author]
To: Crispin Cowan <crispin@...>
Cc: <rmeijer@...>, <apparmor-dev@...>, LSM ML <linux-security-module@...>, linux-kernel@vger.kernel.org <linux-kernel@...>, Arjan van de Ven <arjan@...>
Date: Thursday, November 15, 2007 - 6:58 pm

> > What is left unspecified here is 'how' a child 'with its own profile' is

Sorry have to bring this up.  cgroups why not?  Assign application to
a cgroup that contains there filesystem access permissions.   Done
right this could even be stacked.  Only give less access to
application unless LSM particularly overrides.

Comtainers allow overriding / in chroot style.  This needs file or
label based protection no matter the security framework.  So we don't
have the chroot problems of applications breaking out.

Apparmors file access control features along with selinux's as a
combined into a cgroup would be good.

Same is required for device control.

There are reasons why I keep on bring containers up it changes the
model.  Yes I know coming to a common agreement in these sections will
not be simple.   But at some point it has to be done.
-
Previous message: [thread] [date] [author]
Next message: [thread] [date] [author]

Messages in current thread:
Re: [Apparmor-dev] Re: AppArmor Security Goal, Crispin Cowan, (Tue Nov 13, 4:23 am)
Re: [Apparmor-dev] Re: AppArmor Security Goal, Peter Dolding, (Thu Nov 15, 6:58 pm)