From: John Johansen <john.johansen@canonical.com>
To: "Tetsuo Handa" <penguin-kernel@I-love.SAKURA.ne.jp>,
"Maxime Bélair" <maxime.belair@canonical.com>,
linux-security-module@vger.kernel.org
Cc: paul@paul-moore.com, jmorris@namei.org, serge@hallyn.com,
mic@digikod.net, kees@kernel.org, stephen.smalley.work@gmail.com,
casey@schaufler-ca.com, takedakn@nttdata.co.jp,
linux-api@vger.kernel.org, apparmor@lists.ubuntu.com,
linux-kernel@vger.kernel.org
Subject: Re: [PATCH 2/3] lsm: introduce security_lsm_manage_policy hook
Date: Thu, 8 May 2025 07:44:35 -0700 [thread overview]
Message-ID: <07a496b2-ed1f-4a18-88d1-7be36dba3a8a@canonical.com> (raw)
In-Reply-To: <75c0385c-b649-46b0-907f-903e2217f460@I-love.SAKURA.ne.jp>
On 5/8/25 05:55, Tetsuo Handa wrote:
> On 2025/05/08 17:25, John Johansen wrote:
>> That is fine. But curious I am curious what the interface would look like to fit TOMOYO's
>> needs.
>
> Stream (like "FILE *") with restart from the beginning (like rewind(fp)) support.
> That is, the caller can read/write at least one byte at a time, and written data
> is processed upon encountering '\n'.
>
that can be emulated within the current sycall, where the lsm maintains a buffer.
Are you asking to also read data back out as well, that could be added, but doing
a syscall per byte here or through the fs is going to have fairly high overhead.
Without understanding the requirement it would seem to me, that it would be
better to emulate that file buffer manipulation in userspace similar say C++
stringstreams, and then write the syscall when done.
next prev parent reply other threads:[~2025-05-08 14:44 UTC|newest]
Thread overview: 36+ messages / expand[flat|nested] mbox.gz Atom feed top
2025-05-06 14:32 [PATCH 0/3] lsm: introduce lsm_manage_policy() syscall Maxime Bélair
2025-05-06 14:32 ` [PATCH 1/3] Wire up the lsm_manage_policy syscall Maxime Bélair
2025-05-07 6:26 ` Song Liu
2025-05-07 15:37 ` Maxime Bélair
2025-05-07 22:04 ` Tetsuo Handa
2025-05-08 7:52 ` John Johansen
2025-05-09 10:25 ` Mickaël Salaün
2025-05-11 11:09 ` John Johansen
2025-05-08 6:06 ` Song Liu
2025-05-08 8:18 ` John Johansen
2025-05-09 10:26 ` Mickaël Salaün
2025-05-11 10:47 ` John Johansen
2025-05-12 10:20 ` Mickaël Salaün
2025-05-17 7:59 ` John Johansen
2025-05-08 7:12 ` John Johansen
2025-05-07 13:58 ` kernel test robot
2025-05-06 14:32 ` [PATCH 2/3] lsm: introduce security_lsm_manage_policy hook Maxime Bélair
2025-05-07 6:19 ` Song Liu
2025-05-07 15:37 ` Maxime Bélair
2025-05-08 8:20 ` John Johansen
2025-05-07 10:40 ` Tetsuo Handa
2025-05-07 15:37 ` Maxime Bélair
2025-05-07 20:25 ` Paul Moore
2025-05-08 8:29 ` John Johansen
2025-05-08 16:54 ` Casey Schaufler
2025-05-09 10:26 ` Mickaël Salaün
2025-05-09 14:21 ` Casey Schaufler
2025-05-11 11:26 ` John Johansen
2025-05-11 11:20 ` John Johansen
2025-05-08 8:25 ` John Johansen
2025-05-08 12:55 ` Tetsuo Handa
2025-05-08 14:44 ` John Johansen [this message]
2025-05-08 15:07 ` Tetsuo Handa
2025-05-09 3:25 ` John Johansen
2025-05-07 12:04 ` kernel test robot
2025-05-06 14:32 ` [PATCH 3/3] AppArmor: add support for lsm_manage_policy Maxime Bélair
Reply instructions:
You may reply publicly to this message via plain-text email
using any one of the following methods:
* Save the following mbox file, import it into your mail client,
and reply-to-all from there: mbox
Avoid top-posting and favor interleaved quoting:
https://en.wikipedia.org/wiki/Posting_style#Interleaved_style
* Reply using the --to, --cc, and --in-reply-to
switches of git-send-email(1):
git send-email \
--in-reply-to=07a496b2-ed1f-4a18-88d1-7be36dba3a8a@canonical.com \
--to=john.johansen@canonical.com \
--cc=apparmor@lists.ubuntu.com \
--cc=casey@schaufler-ca.com \
--cc=jmorris@namei.org \
--cc=kees@kernel.org \
--cc=linux-api@vger.kernel.org \
--cc=linux-kernel@vger.kernel.org \
--cc=linux-security-module@vger.kernel.org \
--cc=maxime.belair@canonical.com \
--cc=mic@digikod.net \
--cc=paul@paul-moore.com \
--cc=penguin-kernel@I-love.SAKURA.ne.jp \
--cc=serge@hallyn.com \
--cc=stephen.smalley.work@gmail.com \
--cc=takedakn@nttdata.co.jp \
/path/to/YOUR_REPLY
https://kernel.org/pub/software/scm/git/docs/git-send-email.html
* If your mail client supports setting the In-Reply-To header
via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line
before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox
all inboxes | Powered by JetHome®