From: Chris Wright <chrisw@osdl.org>
To: Mike Waychison <Michael.Waychison@Sun.COM>
Cc: Kyle Moffett <mrmacman_g4@mac.com>,
Tim Hockin <thockin@hockin.org>,
LKML <linux-kernel@vger.kernel.org>,
Rik van Riel <riel@redhat.com>,
ReiserFS List <reiserfs-list@namesys.com>,
Hans Reiser <reiser@namesys.com>
Subject: Re: Using fs views to isolate untrusted processes: I need an assistant architect in the USA for Phase I of a DARPA funded linux kernel project
Date: Wed, 25 Aug 2004 17:56:08 -0700 [thread overview]
Message-ID: <20040825175608.Y1973@build.pdx.osdl.net> (raw)
In-Reply-To: <412D2BD2.2090408@sun.com>; from Michael.Waychison@Sun.COM on Wed, Aug 25, 2004 at 08:16:18PM -0400
* Mike Waychison (Michael.Waychison@Sun.COM) wrote:
> This provides minimal protection if any: the user may remount any block
> devices on any given tree in his 'namespace' (in the sense of "that is
> what we call a mount-table in Linux"). *
Namespaces aren't currently expressive enough, and have caveats like
these, and can't express detailed access controls.
> If I understand what Hans is looking to get done, he's asking for
> someone to architect a system where any given process can be restricted
> to seeing/accessing a subset of the namespace (in the sense of "a tree
> of directories/files"). Eg: process Foo is allowed access to write to
> /etc/group, but _not_ allowed access to /etc/shadow, under any
> circumstances && Foo will be run as root. Hell, maybe Foo is never able
> to even _see_ /etc/shadow (making it a true shadow file :).
This has already been done. LSM provides the infrastructure, things
like LIDS and SubDomain do this fairly directly. SELinux does this as
well using types as an intermediary.
thanks,
-chris
--
Linux Security Modules http://lsm.immunix.org http://lsm.bkbits.net
next prev parent reply other threads:[~2004-08-26 0:58 UTC|newest]
Thread overview: 17+ messages / expand[flat|nested] mbox.gz Atom feed top
2004-08-02 1:20 Hans Reiser
2004-08-25 20:25 ` Rik van Riel
2004-08-25 20:56 ` Tim Hockin
2004-08-25 21:23 ` Mike Waychison
2004-08-26 6:31 ` Hans Reiser
2004-08-26 13:59 ` Stephen Smalley
2004-08-25 23:19 ` Kyle Moffett
2004-08-26 0:16 ` Mike Waychison
2004-08-26 0:50 ` Kyle Moffett
2004-08-26 1:06 ` Chris Wright
2004-08-26 4:16 ` Kyle Moffett
2004-08-26 4:29 ` viro
2004-08-26 4:52 ` Kyle Moffett
2004-08-26 5:01 ` viro
2004-08-26 0:56 ` Chris Wright [this message]
2004-08-26 7:52 ` Hans Reiser
2004-08-26 8:48 ` Hans Reiser
Reply instructions:
You may reply publicly to this message via plain-text email
using any one of the following methods:
* Save the following mbox file, import it into your mail client,
and reply-to-all from there: mbox
Avoid top-posting and favor interleaved quoting:
https://en.wikipedia.org/wiki/Posting_style#Interleaved_style
* Reply using the --to, --cc, and --in-reply-to
switches of git-send-email(1):
git send-email \
--in-reply-to=20040825175608.Y1973@build.pdx.osdl.net \
--to=chrisw@osdl.org \
--cc=Michael.Waychison@Sun.COM \
--cc=linux-kernel@vger.kernel.org \
--cc=mrmacman_g4@mac.com \
--cc=reiser@namesys.com \
--cc=reiserfs-list@namesys.com \
--cc=riel@redhat.com \
--cc=thockin@hockin.org \
/path/to/YOUR_REPLY
https://kernel.org/pub/software/scm/git/docs/git-send-email.html
* If your mail client supports setting the In-Reply-To header
via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line
before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox
Powered by JetHome