Re: [PATCH] ptrace: allow restriction of ptrace scope

Previous message: [thread] [date] [author]
Next message: [thread] [date] [author]
From: Eric W. Biederman
Date: Friday, June 18, 2010 - 6:50 am

Theodore Tso <tytso@MIT.EDU> writes:



If anyone is going to work on this let me make a concrete suggestion.
Let's aim at not stacked lsm's but chained lsm's, and put the chaining
logic in the lsm core.

The core difficulty appears to be how do you multiplex the security pointers
on various objects out there.

My wishlist has this working so that I can logically have a local security
policy in a container, restricted by the global policy but with additional
restrictions.

Eric
--
Previous message: [thread] [date] [author]
Next message: [thread] [date] [author]

Messages in current thread:
[PATCH] ptrace: allow restriction of ptrace scope, Kees Cook, (Wed Jun 16, 3:18 pm)
Re: [PATCH] ptrace: allow restriction of ptrace scope, Roland McGrath, (Wed Jun 16, 4:10 pm)
Re: [PATCH] ptrace: allow restriction of ptrace scope, Roland McGrath, (Wed Jun 16, 5:11 pm)
Re: [PATCH] ptrace: allow restriction of ptrace scope, Eric W. Biederman, (Thu Jun 17, 5:29 am)
Re: [PATCH] ptrace: allow restriction of ptrace scope, James Morris, (Thu Jun 17, 6:45 am)
Re: [PATCH] ptrace: allow restriction of ptrace scope, Eric W. Biederman, (Thu Jun 17, 1:45 pm)
Re: [PATCH] ptrace: allow restriction of ptrace scope, Randy Dunlap, (Thu Jun 17, 2:06 pm)
Re: [PATCH] ptrace: allow restriction of ptrace scope, Serge E. Hallyn, (Thu Jun 17, 3:50 pm)
Re: [PATCH] ptrace: allow restriction of ptrace scope, James Morris, (Thu Jun 17, 4:03 pm)
Re: [PATCH] ptrace: allow restriction of ptrace scope, Eric W. Biederman, (Thu Jun 17, 4:11 pm)
Re: [PATCH] ptrace: allow restriction of ptrace scope, Casey Schaufler, (Thu Jun 17, 8:10 pm)
Re: [PATCH] ptrace: allow restriction of ptrace scope, Theodore Tso, (Fri Jun 18, 3:54 am)
Re: [PATCH] ptrace: allow restriction of ptrace scope, Serge E. Hallyn, (Fri Jun 18, 5:36 am)
Re: [PATCH] ptrace: allow restriction of ptrace scope, Eric W. Biederman, (Fri Jun 18, 6:50 am)
Re: [PATCH] ptrace: allow restriction of ptrace scope, Serge E. Hallyn, (Fri Jun 18, 7:29 am)
Re: [PATCH] ptrace: allow restriction of ptrace scope, Tetsuo Handa, (Fri Jun 18, 7:15 pm)
Re: [PATCH] ptrace: allow restriction of ptrace scope, Casey Schaufler, (Fri Jun 18, 7:23 pm)
Re: [PATCH] ptrace: allow restriction of ptrace scope, Eric W. Biederman, (Fri Jun 18, 7:49 pm)
Re: [PATCH] ptrace: allow restriction of ptrace scope, Frank Ch. Eigler, (Fri Jun 18, 8:19 pm)