Re: [PATCH 2/3] CRED: Split the task security data and move part of it into struct cred

!MAILaRCHIVE_VOTE_RePLACE
Previous message: [thread] [date] [author]
Next message: [thread] [date] [author]
To: Stephen Smalley <sds@...>
Cc: Serge E. Hallyn <serge@...>, David Howells <dhowells@...>, <viro@...>, <hch@...>, <Trond.Myklebust@...>, <casey@...>, <linux-kernel@...>, <selinux@...>, <linux-security-module@...>
Date: Monday, September 24, 2007 - 11:35 am

Quoting Stephen Smalley (sds@tycho.nsa.gov):

Ah, ok, so the daemon would use this to act under the user's
credentials.  I was thinking the user would be using this to act
under the daemon's or kernel's sid.

Between that and David's response, that this is only for the duration of
one syscall (IIUC), and not exported to userspace, it sounds safe
enough at the moment.  I do worry about the fact that inevitably someone
will want to 'expand' on that  :)

My worry arose from the fact that I don't see
security_cred_kernel_act_as() being called anywhere in this patchset...

thanks,
-serge

Previous message: [thread] [date] [author]
Next message: [thread] [date] [author]

Messages in current thread:
[PATCH 0/3] Introduce credential record, David Howells, (Wed Sep 19, 12:17 pm)
[PATCH 1/3] CRED: Introduce a COW credentials record, David Howells, (Wed Sep 19, 12:17 pm)
Re: [PATCH 2/3] CRED: Split the task security data and move ..., Serge E. Hallyn, (Mon Sep 24, 11:35 am)