Re: [RFC][PATCH] security: split ptrace checking in proc

!MAILaRCHIVE_VOTE_RePLACE
Previous message: [thread] [date] [author]
Next message: [thread] [date] [author]
To: Stephen Smalley <sds@...>
Cc: Chris Wright <chrisw@...>, <casey@...>, lsm <linux-security-module@...>, James Morris <jmorris@...>, Eric Paris <eparis@...>, lkml <linux-kernel@...>
Date: Wednesday, May 14, 2008 - 11:28 am

* Stephen Smalley (sds@tycho.nsa.gov) wrote:

fd/ access gives a view in the ->files, which could include rather
internal bits like pipes, sockets, or anonfd descriptors -- things w/out
external handles.  That view includes ability to open the fd (similar
to dup()) and use it (granted subject to further security checks, but
they may be quite generic at that point).

thanks,
-chris
--
Previous message: [thread] [date] [author]
Next message: [thread] [date] [author]

Messages in current thread:
[RFC][PATCH] security: split ptrace checking in proc, Stephen Smalley, (Mon May 12, 8:39 am)
Re: [RFC][PATCH] security: split ptrace checking in proc, Casey Schaufler, (Mon May 12, 10:06 am)
Re: [RFC][PATCH] security: split ptrace checking in proc, Stephen Smalley, (Mon May 12, 11:16 am)
Re: [RFC][PATCH] security: split ptrace checking in proc, Stephen Smalley, (Tue May 13, 10:01 am)
Re: [RFC][PATCH] security: split ptrace checking in proc, Stephen Smalley, (Wed May 14, 7:03 am)
Re: [RFC][PATCH] security: split ptrace checking in proc, Chris Wright, (Wed May 14, 11:28 am)
Re: [RFC][PATCH] security: split ptrace checking in proc, Stephen Smalley, (Wed May 14, 11:50 am)
Re: [RFC][PATCH] security: split ptrace checking in proc, Chris Wright, (Wed May 14, 12:58 pm)