mirror of https://lore.kernel.org/lkml/
 help / color / mirror / Atom feed
From: Petr Baudis <pasky@ucw.cz>
To: linux-kernel@vger.kernel.org, linux-security-module@mail.wirex.com
Cc: greg@kroah.com
Subject: [PATCH] kobject support for LSM core
Date: Mon, 10 Mar 2003 01:13:10 +0100	[thread overview]
Message-ID: <20030310001310.GU3917@pasky.ji.cz> (raw)

  Hello,

  the following patch (against 2.5.64) introduces kobject infrastructure
scaffolding to the LSM framework. It does nothing but allocating security root
subsystem for the LSMs, so that they are tied to one specific point in the
kobject hierarchy. They are suggested to create own subsystems under the
security subsystem, however such things are completely up to the individual
LSMs and not regulated by core in any way (it's not that I would so much like
such an approach, but I was advised so by GregKH and it makes sense in its own
way as well).

  A lot of LSMs use various ad hoc methods for communication with the userspace
and using the sysfs framework could be very convient for them, and there is at
least one real-world (altough yet a bit primitive) LSM which already uses the
security subsystem: http://pasky.ji.cz/securitylevels/.

  It works fine for me and it should be pretty trivial. Please consider
applying.

 security/security.c |   30 ++++++++++++++++++++++++++++++
 1 files changed, 30 insertions(+)

  Kind regards,
				Petr Baudis

--- linux/security/security.c	Sun Mar  9 00:40:32 2003
+++ linux+pasky/security/security.c	Thu Mar  6 23:33:49 2003
@@ -9,11 +9,15 @@
  *	it under the terms of the GNU General Public License as published by
  *	the Free Software Foundation; either version 2 of the License, or
  *	(at your option) any later version.
+ *
+ * Introduced kobject infrastructure.
+ * 2003-02-27 Petr Baudis <pasky@ucw.cz>
  */
 
 #include <linux/config.h>
 #include <linux/module.h>
 #include <linux/init.h>
+#include <linux/kobject.h>
 #include <linux/kernel.h>
 #include <linux/sched.h>
 #include <linux/security.h>
@@ -38,6 +42,7 @@
 	return 0;
 }
 
+
 /**
  * security_scaffolding_startup - initialzes the security scaffolding framework
  *
@@ -59,6 +64,30 @@
 	return 0;
 }
 
+
+/* kobject stuff */
+
+/* We define only the base subsystem here and leave everything to a LSM. It is
+ * heavily recommended that the LSM should create own subsystem under this one,
+ * so that it can be easily made stackable and it doesn't confuse userland by
+ * exporting its stuff directly to /sys/security/. */
+decl_subsys(security,NULL);
+
+/**
+ * security_kobj_init - initializes the security kobject subsystem
+ *
+ * This is called after security_scaffolding_startup as a regular initcall,
+ * since we need sysfs mounted already.
+ */
+static int __init security_kobj_init (void)
+{
+	subsystem_register (&security_subsys);
+	return 0;
+}
+
+subsys_initcall(security_kobj_init);
+
+
 /**
  * register_security - registers a security framework with the kernel
  * @ops: a pointer to the struct security_options that is to be registered
@@ -197,3 +226,4 @@
 EXPORT_SYMBOL_GPL(mod_unreg_security);
 EXPORT_SYMBOL(capable);
 EXPORT_SYMBOL(security_ops);
+EXPORT_SYMBOL(security_subsys);

             reply	other threads:[~2003-03-10  0:02 UTC|newest]

Thread overview: 5+ messages / expand[flat|nested]  mbox.gz  Atom feed  top
2003-03-10  0:13 Petr Baudis [this message]
2003-03-10  6:47 ` Greg KH
2003-03-12 23:20   ` [PATCH] kobject support for LSM core (v2) Petr Baudis
2003-03-13  0:12     ` Greg KH
2003-03-13  0:37     ` Chris Wright

Reply instructions:

You may reply publicly to this message via plain-text email
using any one of the following methods:

* Save the following mbox file, import it into your mail client,
  and reply-to-all from there: mbox

  Avoid top-posting and favor interleaved quoting:
  https://en.wikipedia.org/wiki/Posting_style#Interleaved_style

* Reply using the --to, --cc, and --in-reply-to
  switches of git-send-email(1):

  git send-email \
    --in-reply-to=20030310001310.GU3917@pasky.ji.cz \
    --to=pasky@ucw.cz \
    --cc=greg@kroah.com \
    --cc=linux-kernel@vger.kernel.org \
    --cc=linux-security-module@mail.wirex.com \
    /path/to/YOUR_REPLY

  https://kernel.org/pub/software/scm/git/docs/git-send-email.html

* If your mail client supports setting the In-Reply-To header
  via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox

all inboxes | Powered by JetHome®