[<prev] [next>] [<thread-prev] [thread-next>] [day] [month] [year] [list]
Message-ID: <20101110181000.GC22410@elte.hu>
Date:	Wed, 10 Nov 2010 19:10:00 +0100
From:	Ingo Molnar <mingo@...e.hu>
To:	Andrew Morton <akpm@...ux-foundation.org>
Cc:	Dan Rosenberg <drosenberg@...curity.com>,
	linux-kernel@...r.kernel.org, torvalds@...ux-foundation.org,
	kees.cook@...onical.com
Subject: Re: [PATCH v2] Restrict unprivileged access to kernel syslog
* Andrew Morton <akpm@...ux-foundation.org> wrote:
> OK by me, apart from ...
> 
> a) I'd question the need for the config option.  Are distros really
>    so lame that they can't trust themselves to poke a number into
>    procfs at boot time?
When it comes to security i personally prefer 'permanent' defaults that is a 
property of the booting image. I'd even change the default for the x86 defconfig for 
example - and we could make this option default-y in the future. (We cannot ever 
make the sysctl default itself default-1, it would break compatibility with old 
behavior.)
> b) we have "dmesg_restrict" and "CONFIG_RESTRICT_DMESG".  Less
>    dyslexia, please.
Good point. CONFIG_DMESG_RESTRICT is the proper hierarchical naming i suspect.
Thanks,
	Ingo
--
To unsubscribe from this list: send the line "unsubscribe linux-kernel" in
the body of a message to majordomo@...r.kernel.org
More majordomo info at  http://vger.kernel.org/majordomo-info.html
Please read the FAQ at  http://www.tux.org/lkml/
Powered by blists - more mailing lists
 
