Re: [PATCH] ptrace: allow restriction of ptrace scope

Previous message: [thread] [date] [author]
Next message: [thread] [date] [author]
From: James Morris
Date: Sunday, June 20, 2010 - 5:52 pm

On Fri, 18 Jun 2010, Theodore Tso wrote:


We've already reached a consensus that these things should be put into a 
separate LSM so we can evaluate the possible need for some form of 
stacking or a security library API.

Note that people using SELinux or AppArmor already have the ability to 
restrict ptrace, and they would thus not need to stack this function if it 
were in a separate LSM.

Do you have a use-case where stacking would be useful here?



- James
-- 
James Morris
<jmorris@namei.org>
--
Previous message: [thread] [date] [author]
Next message: [thread] [date] [author]

Messages in current thread:
[PATCH] ptrace: allow restriction of ptrace scope, Kees Cook, (Wed Jun 16, 3:18 pm)
Re: [PATCH] ptrace: allow restriction of ptrace scope, Roland McGrath, (Wed Jun 16, 4:10 pm)
Re: [PATCH] ptrace: allow restriction of ptrace scope, Roland McGrath, (Wed Jun 16, 5:11 pm)
Re: [PATCH] ptrace: allow restriction of ptrace scope, Eric W. Biederman, (Thu Jun 17, 5:29 am)
Re: [PATCH] ptrace: allow restriction of ptrace scope, James Morris, (Thu Jun 17, 6:45 am)
Re: [PATCH] ptrace: allow restriction of ptrace scope, Eric W. Biederman, (Thu Jun 17, 1:45 pm)
Re: [PATCH] ptrace: allow restriction of ptrace scope, Randy Dunlap, (Thu Jun 17, 2:06 pm)
Re: [PATCH] ptrace: allow restriction of ptrace scope, Serge E. Hallyn, (Thu Jun 17, 3:50 pm)
Re: [PATCH] ptrace: allow restriction of ptrace scope, James Morris, (Thu Jun 17, 4:03 pm)
Re: [PATCH] ptrace: allow restriction of ptrace scope, Eric W. Biederman, (Thu Jun 17, 4:11 pm)
Re: [PATCH] ptrace: allow restriction of ptrace scope, Casey Schaufler, (Thu Jun 17, 8:10 pm)
Re: [PATCH] ptrace: allow restriction of ptrace scope, Theodore Tso, (Fri Jun 18, 3:54 am)
Re: [PATCH] ptrace: allow restriction of ptrace scope, Serge E. Hallyn, (Fri Jun 18, 5:36 am)
Re: [PATCH] ptrace: allow restriction of ptrace scope, Eric W. Biederman, (Fri Jun 18, 6:50 am)
Re: [PATCH] ptrace: allow restriction of ptrace scope, Serge E. Hallyn, (Fri Jun 18, 7:29 am)
Re: [PATCH] ptrace: allow restriction of ptrace scope, Tetsuo Handa, (Fri Jun 18, 7:15 pm)
Re: [PATCH] ptrace: allow restriction of ptrace scope, Casey Schaufler, (Fri Jun 18, 7:23 pm)
Re: [PATCH] ptrace: allow restriction of ptrace scope, Eric W. Biederman, (Fri Jun 18, 7:49 pm)
Re: [PATCH] ptrace: allow restriction of ptrace scope, Frank Ch. Eigler, (Fri Jun 18, 8:19 pm)
Re: [PATCH] ptrace: allow restriction of ptrace scope, James Morris, (Sun Jun 20, 5:52 pm)
Re: [PATCH] ptrace: allow restriction of ptrace scope, Valdis.Kletnieks, (Sun Jun 20, 7:16 pm)