Re: [PATCH] cgroups: implement device whitelist lsm (v3)

Previous message: [thread] [date] [author]
Next message: [thread] [date] [author]
From: Serge E. Hallyn
Date: Monday, March 17, 2008 - 7:08 am

Quoting Casey Schaufler (casey@schaufler-ca.com):

No I'd like to see those patches.  It would ideally allow LSM to become
*purely* restrictive and LPM to be purely empowering, presumably making
the resulting hook sets easier to review and maintain.  The LPM wouldn't
(I assume) gain any *new* hook points so we wouldn't be adding any new
places for hooks to be overriden by a rootkit.

-serge
--
Previous message: [thread] [date] [author]
Next message: [thread] [date] [author]

Messages in current thread:
[PATCH] cgroups: implement device whitelist lsm (v3), Serge E. Hallyn, (Thu Mar 13, 7:41 am)
Re: [PATCH] cgroups: implement device whitelist lsm (v3), Stephen Smalley, (Fri Mar 14, 6:27 am)
Re: [PATCH] cgroups: implement device whitelist lsm (v3), Serge E. Hallyn, (Fri Mar 14, 7:32 am)
Re: [PATCH] cgroups: implement device whitelist lsm (v3), Stephen Smalley, (Fri Mar 14, 10:41 am)
Re: [PATCH] cgroups: implement device whitelist lsm (v3), Casey Schaufler, (Fri Mar 14, 3:44 pm)
Re: [PATCH] cgroups: implement device whitelist lsm (v3), Stephen Smalley, (Mon Mar 17, 6:26 am)
Re: [PATCH] cgroups: implement device whitelist lsm (v3), Serge E. Hallyn, (Mon Mar 17, 7:08 am)
Re: [PATCH] cgroups: implement device whitelist lsm (v3), Casey Schaufler, (Mon Mar 17, 9:16 am)
Re: [PATCH] cgroups: implement device whitelist lsm (v3), Stephen Smalley, (Mon Mar 17, 9:48 am)