[<prev] [next>] [<thread-prev] [thread-next>] [day] [month] [year] [list]
Message-ID: <395440.2938.qm@web36606.mail.mud.yahoo.com>
Date: Tue, 11 Dec 2007 13:18:12 -0800 (PST)
From: Casey Schaufler <casey@...aufler-ca.com>
To: David Howells <dhowells@...hat.com>,
Stephen Smalley <sds@...ho.nsa.gov>
Cc: dhowells@...hat.com, Karl MacMillan <kmacmill@...hat.com>,
viro@....linux.org.uk, hch@...radead.org,
Trond.Myklebust@...app.com, casey@...aufler-ca.com,
linux-kernel@...r.kernel.org, selinux@...ho.nsa.gov,
linux-security-module@...r.kernel.org
Subject: Re: [PATCH 08/28] SECURITY: Allow kernel services to override LSM settings for task actions [try #2]
--- David Howells <dhowells@...hat.com> wrote:
...
>
> How about I just stick the context in /etc/cachefilesd.conf as a textual
> configuration item and have the daemon pass that as a string to the
> cachefiles
> kernel module, which can then ask LSM if it's valid to set this context as an
> override, given the daemon's own security context? That seems entirely
> reasonable to me.
Works for Smack. I can't say definitively, but I think it will
work for SELinux. Beyond that and we're into the fuzzy bit of the
LSM.
Casey Schaufler
casey@...aufler-ca.com
--
To unsubscribe from this list: send the line "unsubscribe linux-kernel" in
the body of a message to majordomo@...r.kernel.org
More majordomo info at http://vger.kernel.org/majordomo-info.html
Please read the FAQ at http://www.tux.org/lkml/
Powered by blists - more mailing lists