Re: [AppArmor 01/41] Pass struct vfsmount to the inode_create LSM hook

!MAILaRCHIVE_VOTE_RePLACE
Previous message: [thread] [date] [author]
Next message: [thread] [date] [author]
To: Kyle Moffett <mrmacman_g4@...>
Cc: <casey@...>, Andreas Gruenbacher <agruen@...>, James Morris <jmorris@...>, <linux-kernel@...>, <linux-security-module@...>, <linux-fsdevel@...>
Date: Sunday, May 27, 2007 - 4:34 am

>> On the other hand, if you actually want to protect the _data_, then 
tagging the _name_ is flawed; tag the *DATA* instead.

Would it make sense to label the data (resource) with a list of paths 
(names) that can be used to access it?

Therefore the data would be protected against being accessed via 
alternative arbitrary names. This may be a simple label to maintain and 
(possibly to) enforce, allowing path based confinement to protect a 
resource. This may allow for the benefits of pathname based confinement 
while avoiding some of its problems.

Obviously this would not protect against a pathname pointing to 
arbitrary data…


Just a thought.

Z. Cliffe Schreuders.


-
Previous message: [thread] [date] [author]
Next message: [thread] [date] [author]

Messages in current thread:
Re: [AppArmor 01/41] Pass struct vfsmount to the inode_creat..., Andreas Gruenbacher, (Thu May 24, 2:10 pm)
Re: [AppArmor 01/41] Pass struct vfsmount to the inode_creat..., Cliffe, (Sun May 27, 4:34 am)
Re: [AppArmor 01/41] Pass struct vfsmount to the inode_creat..., Toshiharu Harada, (Tue May 29, 10:38 pm)
Re: [AppArmor 01/41] Pass struct vfsmount to the inode_creat..., Andreas Gruenbacher, (Sat May 26, 7:46 am)
Re: Pass struct vfsmount to the inode_create LSM hook, Tetsuo Handa, (Sat May 26, 8:09 am)
Re: Pass struct vfsmount to the inode_create LSM hook, Andreas Gruenbacher, (Sat May 26, 9:41 am)
Re: Pass struct vfsmount to the inode_create LSM hook, Tetsuo Handa, (Sat May 26, 10:44 am)
Re: Pass struct vfsmount to the inode_create LSM hook, Kyle Moffett, (Sat May 26, 2:16 pm)
Re: Pass struct vfsmount to the inode_create LSM hook, Andreas Gruenbacher, (Sat May 26, 12:52 pm)
Re: [AppArmor 01/41] Pass struct vfsmount to the inode_creat..., Jeremy Maitin-Shepard, (Fri May 25, 1:17 am)
Re: [AppArmor 01/41] Pass struct vfsmount to the inode_creat..., Andreas Gruenbacher, (Fri May 25, 4:00 pm)
Re: [AppArmor 01/41] Pass struct vfsmount to the inode_creat..., Andreas Gruenbacher, (Sat May 26, 10:05 am)
Re: [AppArmor 01/41] Pass struct vfsmount to the inode_creat..., Jeremy Maitin-Shepard, (Fri May 25, 2:10 pm)
Re: [AppArmor 01/41] Pass struct vfsmount to the inode_creat..., Andreas Gruenbacher, (Sat May 26, 8:10 am)
Re: [AppArmor 01/41] Pass struct vfsmount to the inode_creat..., Jeremy Maitin-Shepard, (Fri May 25, 2:13 pm)
Re: [AppArmor 01/41] Pass struct vfsmount to the inode_creat..., Andreas Gruenbacher, (Fri May 25, 12:14 am)
Re: [AppArmor 01/41] Pass struct vfsmount to the inode_creat..., Andreas Gruenbacher, (Thu May 24, 5:56 pm)