Re: Preview of changes to the Security susbystem for 2.6.36

Previous message: [thread] [date] [author]
Next message: [thread] [date] [author]
From: Christoph Hellwig
Date: Monday, August 2, 2010 - 5:24 am

On Mon, Aug 02, 2010 at 12:18:46PM +1000, James Morris wrote:

I'm also happy to do it on-list, but I really didn't want to do it
before I've actually validated the patches in your tree still are the
same that were objected before.

As mentioned a few times during the past discussion moving broken
code into a LSM doesn't magically fix it.  In fact YAMA is not any kind
of (semi-)coherent security policy like Selinux, smack or similar but
just a random set of hacks that you didn't get past the subsystem
maintainers.

Al gave you some very clear advice how a the sticky check should be
done for symlinks (if we need it at all, which I tend to disagree with),
and the ptrace check completely breaks crash handlers that we have
in all kinds of applications.  If you can get it into the main ptrace
code past Roland and Oleg that's fine, but just pushing it out into
a tree that has percieved easier merge criteria doesn't work.
--
Previous message: [thread] [date] [author]
Next message: [thread] [date] [author]

Messages in current thread:
Preview of changes to the Security susbystem for 2.6.36, James Morris, (Fri Jul 30, 1:59 am)
Re: Preview of changes to the Security susbystem for 2.6.36, Christian Stroetmann, (Mon Aug 2, 3:19 am)
Re: Preview of changes to the Security susbystem for 2.6.36, Christoph Hellwig, (Mon Aug 2, 5:24 am)
Re: Preview of changes to the Security susbystem for 2.6.36, Serge E. Hallyn, (Mon Aug 2, 11:08 am)
Re: Preview of changes to the Security susbystem for 2.6.36, Christian Stroetmann, (Mon Aug 2, 11:50 am)
Re: Preview of changes to the Security susbystem for 2.6.36, Valdis.Kletnieks, (Mon Aug 2, 11:51 am)
Re: Preview of changes to the Security susbystem for 2.6.36, Valdis.Kletnieks, (Tue Aug 3, 2:38 pm)
Re: Preview of changes to the Security susbystem for 2.6.36, Christian Stroetmann, (Tue Aug 3, 2:52 pm)
Re: Preview of changes to the Security susbystem for 2.6.36, Valdis.Kletnieks, (Tue Aug 3, 7:07 pm)
Re: Preview of changes to the Security susbystem for 2.6.36, Valdis.Kletnieks, (Tue Aug 3, 11:18 pm)
Re: Preview of changes to the Security susbystem for 2.6.36, Christian Stroetmann, (Wed Aug 4, 5:21 am)
Re: Preview of changes to the Security susbystem for 2.6.36, Valdis.Kletnieks, (Wed Aug 4, 9:23 am)