Re: [PATCH] Version 3 (2.6.23-rc8) Smack: Simplified Mandatory Access Control Kernel

!MAILaRCHIVE_VOTE_RePLACE
Previous message: [thread] [date] [author]
Next message: [thread] [date] [author]
To: Casey Schaufler <casey@...>
Cc: <torvalds@...>, <linux-security-module@...>, <linux-kernel@...>, <akpm@...>
Date: Sunday, September 30, 2007 - 11:47 pm

Quoting Casey Schaufler (casey@schaufler-ca.com):

Ok, so to control smack label transitions, basically you would
run with CAP_MAC_OVERRIDE (see my note later) so that you're
allowed to change your smack label by writing to
/proc/self/attr/current, then you drop CAP_MAC_OVERRIDE, then you're
no longer able to change your label?  I.e. no inherent label changing
rules through smack itself?

Just making sure I have that right.  If I do, then I think at least
defining the word 'privileged' above, given that this is mac,
would help.


Might point out that no other modules must be compiled in along with
smack, and that smack will do posix capabilities.


Are you sure this isn't something you'd like to really audit?

(Sorry if that's been asked before)


We're basically inevitably going to be switching to 64-bit caps
"any day now".  Should we just go ahead and do it here?  Now
maybe we should use a less contraversial name than 'mac override'
like 'CAP_MAC_POLICY_ADMIN' :), but I guess CAP_MAC_OVERRIDE
is honest.

(I had started a 64-bit caps patch, but then got stuck trying to
decide whether something needed to be done about
task_capability_lock...)

Well, I guess you wouldn't want to bog down your patch to
that, but would you take your own bit once it was available,
or are you happy just using CAP_LINUX_IMMUTABLE?

Previous message: [thread] [date] [author]
Next message: [thread] [date] [author]

Messages in current thread:
Re: [PATCH] Version 3 (2.6.23-rc8) Smack: Simplified Mandato..., Serge E. Hallyn, (Sun Sep 30, 11:47 pm)
Re: [PATCH] Version 3 (2.6.23-rc8) Smack: Simplified Mandato..., Eric W. Biederman, (Fri Oct 5, 12:45 am)
Re: [PATCH] Version 3 (2.6.23-rc8) Smack: Simplified Mandato..., Kazuki Omo(Company), (Tue Oct 30, 12:01 am)
Re: [PATCH] Version 3 (2.6.23-rc8) Smack: Simplified Mandato..., Eric W. Biederman, (Wed Oct 10, 9:48 am)
Re: [PATCH] Version 3 (2.6.23-rc8) Smack: Simplified Mandato..., Christoph Hellwig, (Sun Sep 30, 5:53 am)