Re: [PATCH 3/3] security: allow capable check to permit mmap or low vm space

Previous message: [thread] [date] [author]
Next message: [thread] [date] [author]
From: Eric Paris
Date: Tuesday, November 20, 2007 - 9:54 am

On Sat, 2007-11-17 at 09:12 +1100, James Morris wrote:

It was placed in CONFIG_SECURITY so that users can (If their given LSM
supports it) selectively allow this stuff.  Some LSMs are fine grained
enough to allow applications like dosemu and X to use low pages without
globally disabling.  I can't think of any reasonable way to move all of
this into base kernel code while still allowing overrides.

I'd love to hear suggestions on how to move all of this out of the
security code and into the base kernel while not neglecting those few
users who need this functionality.

-Eric

-
Previous message: [thread] [date] [author]
Next message: [thread] [date] [author]

Messages in current thread:
Re: [PATCH 3/3] security: allow capable check to permit mm ..., Eric Paris, (Tue Nov 20, 9:54 am)