Re: [RFC][PATCH v2] security: split proc ptrace checking into read vs. attach

Previous message: [thread] [date] [author]
Next message: [thread] [date] [author]
From: Serge E. Hallyn
Date: Thursday, May 15, 2008 - 12:37 pm

Quoting Stephen Smalley (sds@tycho.nsa.gov):

I personally would call them something like PTRACE_MODE_MONITOR and
PTRACE_MODE_CONTROL.  Though PTRACE_MODE_MONITOR probably means less
than _READ to most people, but they seem more consistent with being
ptrace flags.  But I'm not asking you to change them.

Overall the split makes sense.

In this particular case, would it be worthwhile to also split
check_mem_permission or pass it a mode bit?  Note that two of the
three calls are for read permission only.


Surprisingly, much easier to think about, thanks.

--
Previous message: [thread] [date] [author]
Next message: [thread] [date] [author]

Messages in current thread:
[RFC][PATCH v2] security: split proc ptrace checking into ..., Stephen Smalley, (Thu May 15, 11:56 am)
Re: [RFC][PATCH v2] security: split proc ptrace checking ..., Casey Schaufler, (Thu May 15, 12:25 pm)
Re: [RFC][PATCH v2] security: split proc ptrace checking ..., Serge E. Hallyn, (Thu May 15, 12:37 pm)
Re: [RFC][PATCH v2] security: split proc ptrace checking ..., Stephen Smalley, (Thu May 15, 12:45 pm)