We've already reached a consensus that these things should be put into a
separate LSM so we can evaluate the possible need for some form of
stacking or a security library API.
Note that people using SELinux or AppArmor already have the ability to
restrict ptrace, and they would thus not need to stack this function if it
were in a separate LSM.
Do you have a use-case where stacking would be useful here?
- James
--
James Morris
<jmorris@namei.org>
--