Christos Zoulas wrote:I'm sorry if that part of my mail wasn't clear, but the user will be able to choose between "traditional securelevel model" and "fine- grained knobs". In the latter case, kern.securelevel will have no meaning in the NetBSD kernel at all -- there will no longer be "security levels"; rather a collection of knobs you'll be able to manipulate. The securelevel variable will exist only for [binary] compatibility with third-party software/LKMs. Of course, the /etc/rd.d/securelevel script for systems with multiple knobs will be changed to load sysctl.conf-like files with customized settings made by the admin. We should supply skeleton files with the possible knobs and provide documentation on the meaning of each knob and what securelevel it used to belong to. On systems with multiple knobs exposed, maintaining correlation between the securelevel variable and the value(s) of these knobs can be done similar to what David suggested, assuming that it will set securelevel to 2, even if only one securelevel 2 knob was set. I addressed this in my post.. in the case of traditional securelevel, we don't need to worry about that. When we have multiple knobs, we would save the state of securelevel, then set it to a predefined mask, say SECURELEVEL_MASK_0 (or whatever). When returning back to multi-user, we will restore the saved state. Hope this answers your questions, -e. -- Elad Efrat
| Karl Meyer | PROBLEM: 2.6.23-rc "NETDEV WATCHDOG: eth0: transmit timed out" |
| David Miller | Slow DOWN, please!!! |
| Mark Fasheh | [PATCH 0/39] Ocfs2 updates for 2.6.28 |
| Bart Van Assche | Integration of SCST in the mainstream Linux kernel |
git: | |
| Shawn O. Pearce | Re: pack operation is thrashing my server |
| Pierre Habouzit | git send-email improvements |
| Matthieu Moy | git push to a non-bare repository |
| Shawn O. Pearce | libgit2 - a true git library |
| Elad Efrat | Integrating securelevel and kauth(9) |
| Hubert Feyrer | Re: Compressed vnd handling tested successfully |
| Lord Isildur | Re: Fork bomb protection patch |
| Matt Thomas | Re: FFS journal |
| Will Maier | cron doesn't run commands in /etc/crontab? |
| Richard Stallman | Real men don't attack straw men |
| Harald Dunkel | Re: Packet Filter: how to keep device names on hardware failure? |
| Jordi Espasa Clofent | Resolving dependencies with pkg_add |
| Question on swap as ramdisk partition | 56 minutes ago | Linux kernel |
| Netfilter kernel module | 11 hours ago | Linux kernel |
| serial driver xmit problem | 14 hours ago | Linux kernel |
| Why Windows is better than Linux | 14 hours ago | Linux general |
| How can I see my kernel messages in vt12? | 21 hours ago | Linux kernel |
| Grub | 1 day ago | Linux general |
| vmalloc_fault handling in x86_64 | 1 day ago | Linux kernel |
| epoll_wait()ing on epoll FD | 1 day ago | Linux kernel |
| Framebuffer in x86_64 causes problems to multiseat | 1 day ago | Linux kernel |
| Difference between 2.4 and 2.6 regarding thread creation | 2 days ago | Linux general |
