Re: [PATCH 1/1] cgroups: implement device whitelist (v6)

!MAILaRCHIVE_VOTE_RePLACE
Previous message: [thread] [date] [author]
Next message: [thread] [date] [author]
To: Pavel Machek <pavel@...>
Cc: Serge E. Hallyn <serue@...>, lkml <linux-kernel@...>, <daniel@...>, <lizf@...>, Pavel Emelyanov <xemul@...>, Greg KH <greg@...>, Andrew Morton <akpm@...>
Date: Monday, March 31, 2008 - 10:00 am

Quoting Pavel Machek (pavel@ucw.cz):

No.  At the moment SELinux can't authorize based on type/major:minor.  I
would like to add that support later on, but even when I do, folks such
as the openvz folks do not want to rely on any security modules.


Until the part of Miklos' user mounts patches go in which enforces MNT_NODEV
on mounts made by someone who is !capable(CAP_MKNOD), using capability bounding
sets is completely inadequate.


What's ugly about it?  How could we clean it up?


Huh?

-serge
--
Previous message: [thread] [date] [author]
Next message: [thread] [date] [author]

Messages in current thread:
[PATCH 1/1] cgroups: implement device whitelist (v6), Serge E. Hallyn, (Wed Mar 26, 2:05 pm)
Re: [PATCH 1/1] cgroups: implement device whitelist (v6), Serge E. Hallyn, (Mon Mar 31, 10:00 am)
Re: [PATCH 1/1] cgroups: implement device whitelist (v6), Serge E. Hallyn, (Tue Apr 1, 6:07 pm)
Re: [PATCH 1/1] cgroups: implement device whitelist (v6), Alexey Dobriyan, (Tue Apr 1, 8:34 am)
Re: [PATCH 1/1] cgroups: implement device whitelist (v6), Andrew Morton, (Thu Mar 27, 5:04 am)
Re: [PATCH 1/1] cgroups: implement device whitelist (v6), Serge E. Hallyn, (Thu Mar 27, 12:24 pm)
Re: [PATCH 1/1] cgroups: implement device whitelist (v6), Serge E. Hallyn, (Thu Mar 27, 1:37 pm)