login
Header Space

 
 

Mailing list archives

Search results

Found 11 matching messages (0.051 seconds). Page 1 of 1.

Re: [AppArmor 00/44] AppArmor security module overview

... 2007 at 07:47:00PM -0700, Andrew Morton wrote: > On Tue, 26 Jun 2007 19:24:03 -0700 John Johansen wrot= e: >=20 > > >=20 > > > so... where do we stand with this? Fundamental, irreconcilable > > ...

linux-fsdevel - John Johansen - Jun 27 2007 - 02:43

Re: [AppArmor 39/41] AppArmor: Profile loading and manipulation, pathname matching

... to care. >=20 > A security system that allows to crash the kernel is a little weird=20 > though. It would be better to check. Not that a recursion check > is particularly expensive. >=20 Indeed. It will be fixed in the next rev. thanks john

linux-fsdevel - John Johansen - Apr 16 2007 - 16:56

Re: [AppArmor 38/41] AppArmor: Module and LSM hooks

... 's that could be potentially used to elevated priledge. The check is inconsistent with AppArmor's model and we should be modelling sysctl accesses as pathname access, and then we could be using standard mediation. thanks for the review john

linux-fsdevel - John Johansen - Apr 16 2007 - 17:37

AppArmor FAQ

Here we present our direct responses to the most frequent questions from the AppArmor from the 2006 post. Use of Pathnames For Access Control ----------------------------------- Some people in the security field believe that pathnames are an

linux-fsdevel - John Johansen - Apr 16 2007 - 17:33

Re: [AppArmor 39/41] AppArmor: Profile loading and manipulation, pathname matching

On Mon, Apr 16, 2007 at 11:00:01PM +0100, Alan Cox wrote: > > don't actually have to care --- if loading an invalid profile can bring= down=20 > > the system, then that's no worse than an arbitrary module that crashes = the=20 > > machine. Not sure

linux-fsdevel - John Johansen - Apr 16 2007 - 18:11

Re: [AppArmor 00/45] AppArmor security module overview

and with the actual introductory text this time This post contains patches to include the AppArmor application security framework, with request for inclusion. It contains fixes for almost all of the feedback received from the previous post. A

linux-fsdevel - John Johansen - May 14 2007 - 09:50

Re: [RFD Patch 0/4] AppArmor - Don't pass NULL nameidata to vfs_create/lookup/permission IOPs

sigh, and with the intoductory text attached This post is a request for discussion on creating a second minimal nameidata struct to eliminate conditionally passing of vfsmounts to the LSM. It contains a series of patches that apply on top of the

linux-fsdevel - John Johansen - May 14 2007 - 09:51

Re: [AppArmor 39/45] AppArmor: Profile loading and manipulation, pathname matching

On Thu, Jun 21, 2007 at 10:21:07PM +0200, Lars Marowsky-Bree wrote: > On 2007-06-21T22:07:40, Pavel Machek wrote: >=20 > >=20 > > Plus IIRC we have something like "AA has to allocate path-sized > > buffers along every syscall". >=20

linux-fsdevel - John Johansen - Jun 21 2007 - 19:25

Re: [AppArmor 39/45] AppArmor: Profile loading and manipulation, pathname matching

On Thu, Jun 21, 2007 at 09:06:40PM -0400, James Morris wrote: > On Thu, 21 Jun 2007, Chris Mason wrote: >=20 > > > The incomplete mediation flows from the design, since the pathname-ba= sed > > > mediation doesn't generalize to cover all objects

linux-fsdevel - John Johansen - Jun 22 2007 - 03:40

Re: [AppArmor 39/45] AppArmor: Profile loading and manipulation, pathname matching

On Thu, Jun 21, 2007 at 04:59:54PM -0400, Stephen Smalley wrote: > On Thu, 2007-06-21 at 21:54 +0200, Lars Marowsky-Bree wrote: > > On 2007-06-21T15:42:28, James Morris wrote: > >=20 >=20 > > And now, yes, I know AA doesn't

linux-fsdevel - John Johansen - Jun 22 2007 - 04:06

Re: [AppArmor 00/44] AppArmor security module overview

On Tue, Jun 26, 2007 at 04:52:02PM -0700, Andrew Morton wrote: > On Tue, 26 Jun 2007 16:07:56 -0700 > jjohansen@suse.de wrote: >=20 > > This post contains patches to include the AppArmor application security > > framework, with request for inclusion

linux-fsdevel - John Johansen - Jun 26 2007 - 22:24

speck-geostationary