Re: [PATCH 0/3] Taming execve, setuid, and LSMs

Previous message: [thread] [date] [author]
Next message: [thread] [date] [author]
From: Serge E. Hallyn
Date: Monday, April 19, 2010 - 2:39 pm

Quoting Andrew Lutomirski (luto@mit.edu):

No, please see the rest of that thread - that was an oversight.


hmm...

A good point.


Absolutely these should not be ignored, and Eric didn't mean to ignore
them.


I do not agree with deciding the admins are not competent to admin
their system and therefore we should bypass them and let users decide.

But it's moot, as I think you've convinced me with your point 1. above
to take another look at your patches.


Yes, but that's a reason to aim for targeted caps.  Exec_nopriv or
whatever is more a sandbox than a namespace feature.


Not sure what you mean by that last part - inside the sandbox, you won't
get capabilities, targeted or otherwise, but certainly targeted capabilities
and a sandbox are not mutually exclusive.

Thanks for responding, I'll take another look at your patchset in detail.

thanks,
-serge
--
Previous message: [thread] [date] [author]
Next message: [thread] [date] [author]

Messages in current thread:
[PATCH 0/3] Taming execve, setuid, and LSMs, Andy Lutomirski, (Fri Mar 26, 6:38 am)
Re: [PATCH 0/3] Taming execve, setuid, and LSMs, Serge E. Hallyn, (Mon Apr 19, 10:26 am)
Re: [PATCH 0/3] Taming execve, setuid, and LSMs, Andrew Lutomirski, (Mon Apr 19, 2:32 pm)
Re: [PATCH 0/3] Taming execve, setuid, and LSMs, Serge E. Hallyn, (Mon Apr 19, 2:39 pm)
Re: [PATCH 0/3] Taming execve, setuid, and LSMs, Andrew Lutomirski, (Mon Apr 19, 3:02 pm)
Re: [PATCH 0/3] Taming execve, setuid, and LSMs, Serge E. Hallyn, (Mon Apr 19, 3:25 pm)
Re: [PATCH 0/3] Taming execve, setuid, and LSMs, Stephen Smalley, (Tue Apr 20, 5:37 am)
Re: [PATCH 0/3] Taming execve, setuid, and LSMs, Andrew Lutomirski, (Tue Apr 20, 7:23 am)
Re: [PATCH 0/3] Taming execve, setuid, and LSMs, Serge E. Hallyn, (Tue Apr 20, 7:35 am)
Re: [PATCH 0/3] Taming execve, setuid, and LSMs, Andrew Lutomirski, (Tue Apr 20, 8:11 am)
Re: [PATCH 0/3] Taming execve, setuid, and LSMs, Stephen Smalley, (Tue Apr 20, 8:34 am)
Re: [PATCH 0/3] Taming execve, setuid, and LSMs, Andrew Lutomirski, (Tue Apr 20, 8:53 am)
Re: [PATCH 0/3] Taming execve, setuid, and LSMs, Andrew Lutomirski, (Tue Apr 20, 6:37 pm)
Re: [PATCH 0/3] Taming execve, setuid, and LSMs, Serge E. Hallyn, (Tue Apr 20, 7:25 pm)
Re: [PATCH 0/3] Taming execve, setuid, and LSMs, Stephen Smalley, (Wed Apr 21, 5:34 am)
Re: [PATCH 0/3] Taming execve, setuid, and LSMs, Andrew Lutomirski, (Wed Apr 21, 2:15 pm)
Re: [PATCH 0/3] Taming execve, setuid, and LSMs, Serge E. Hallyn, (Wed Apr 21, 3:30 pm)
Re: [PATCH 0/3] Taming execve, setuid, and LSMs, Andy Lutomirski, (Wed Apr 21, 4:42 pm)