Aloha James, Aloha Kees;
Ont the 02.08.2010 08:57, Kees Cook wrote:
A private NAK against a company's developer's OK
Where is the difference private and company? I thought that it doesn't
matter who and what a developer is, and where she/he comes from.
The opinion as well as the NAK by Christoph was discussed and supported
by other developers.
Yes, because it supports as an experiment the development of the LSM
architecture in general.
That is not quite right.
It is correct that this special Yama LSM was accepted so far. The
inclusion into mainline was not an issue at that time.
But we discussed as well that the problem of chaining of small or large
LSMs is not an argument for the existence of the Yama LSM, and that the
LSM architecture should be developed further so that all of the
functionalities of other securtiy packages without an LSM can be
integrated as a whole by a new version of the LSM system in the future
and not by ripping them of like it was done with the Yama LSM [3].
You can see these objections [3] as a second NAK, but now from a
company's developer (I haven't said this before, because I'm not a hard
core kernel developer).
[3] http://lkml.org/lkml/2010/6/30/64
Have fun in the sun
Christian Stroetmann
--