Re: [PATCH 5/9] Make use of permissions, returned by kobj_lookup

Previous message: [thread] [date] [author]
Next message: [thread] [date] [author]
From: Stephen Smalley
Date: Wednesday, March 12, 2008 - 6:27 am

On Wed, 2008-03-12 at 09:18 -0400, Stephen Smalley wrote:

Also, note that "real" device labeling and access control (i.e. bind a
label to a device in the kernel irrespective of what device node is used
to access it so that a process that can create any device nodes at all
can't effectively bypass all device access controls just by creating an
arbitrary node to any device in a type accessible to it) is already
called out on our kernel todo list for SELinux, and contributions there
would be welcome.  

-- 
Stephen Smalley
National Security Agency

--
Previous message: [thread] [date] [author]
Next message: [thread] [date] [author]

Messages in current thread:
[PATCH 0/9] Devices accessibility control group (v4), Pavel Emelyanov, (Wed Mar 5, 10:23 am)
[PATCH 1/9] Avoid magic constants in drivers/base/map.c, Pavel Emelyanov, (Wed Mar 5, 10:25 am)
[PATCH 2/9] Cleanup the get_gendisk() a bit, Pavel Emelyanov, (Wed Mar 5, 10:28 am)
[PATCH 3/9] Add a mode on the struct probe, Pavel Emelyanov, (Wed Mar 5, 10:32 am)
[PATCH 5/9] Make use of permissions, returned by kobj_lookup, Pavel Emelyanov, (Wed Mar 5, 10:37 am)
[PATCH 6/9] Extend the drivers/base/map.c functionality, Pavel Emelyanov, (Wed Mar 5, 10:40 am)
[PATCH 9/9] Devices accessibility control group itself, Pavel Emelyanov, (Wed Mar 5, 10:47 am)
Re: [PATCH 0/9] Devices accessibility control group (v4), Serge E. Hallyn, (Wed Mar 5, 8:15 pm)
Re: [PATCH 0/9] Devices accessibility control group (v4), Pavel Emelyanov, (Thu Mar 6, 1:36 am)
Re: [PATCH 0/9] Devices accessibility control group (v4), Pavel Emelyanov, (Fri Mar 7, 1:54 am)
Re: [PATCH 5/9] Make use of permissions, returned by kobj_ ..., Stephen Smalley, (Wed Mar 12, 6:27 am)