Re: [AppArmor 39/45] AppArmor: Profile loading and manipulation, pathname matching

Previous message: [thread] [date] [author]
Next message: [thread] [date] [author]
From: David Wagner
Date: Sunday, June 24, 2007 - 2:20 pm

James Morris  wrote:

I don't see it.  I don't see why you call this a design issue.  Isn't
this just a case where they haven't gotten around to implementing
network and IPC mediation yet?  How is that a design issue arising
from a pathname-based model?  For instance, one system I built (Janus)
provided complete mediation, including mediation of network and IPC,
yet it too used a pathname model for its policy file when describing
the policy for the filesystem.  That seems to contradict your statement.
-
Previous message: [thread] [date] [author]
Next message: [thread] [date] [author]

Messages in current thread:
Re: [AppArmor 39/45] AppArmor: Profile loading and manipul ..., David Wagner, (Sun Jun 24, 2:20 pm)