Re: [RFC][PATCH] security: split ptrace checking in proc

Previous message: [thread] [date] [author]
Next message: [thread] [date] [author]
From: Stephen Smalley
Date: Wednesday, May 14, 2008 - 8:50 am

On Wed, 2008-05-14 at 08:28 -0700, Chris Wright wrote:

What do you mean by "generic" in the above?  Just the fact that there
wouldn't be any distinction between such access and access to a
descriptor received explicitly via local IPC from the target task?

Ok, so perhaps the only distinction that makes sense is read vs.
write/control, with all checks within proc except mem_write using the
former and ptrace_attach and mem_write using the latter?

-- 
Stephen Smalley
National Security Agency

--
Previous message: [thread] [date] [author]
Next message: [thread] [date] [author]

Messages in current thread:
[RFC][PATCH] security: split ptrace checking in proc, Stephen Smalley, (Mon May 12, 5:39 am)
Re: [RFC][PATCH] security: split ptrace checking in proc, Casey Schaufler, (Mon May 12, 7:06 am)
Re: [RFC][PATCH] security: split ptrace checking in proc, Stephen Smalley, (Mon May 12, 8:16 am)
Re: [RFC][PATCH] security: split ptrace checking in proc, Stephen Smalley, (Tue May 13, 7:01 am)
Re: [RFC][PATCH] security: split ptrace checking in proc, Stephen Smalley, (Wed May 14, 4:03 am)
Re: [RFC][PATCH] security: split ptrace checking in proc, Stephen Smalley, (Wed May 14, 8:50 am)