mirror of https://lore.kernel.org/lkml/
 help / color / mirror / Atom feed
From: Kurt Garloff <garloff@suse.de>
To: Amon Ott <ao@rsbac.org>
Cc: rsbac@rsbac.org,
	"Lorenzo Hernández García-Hierro" <lorenzo@gnu.org>,
	"linux-kernel@vger.kernel.org" <linux-kernel@vger.kernel.org>,
	"linux-security-module@wirex.com"
	<linux-security-module@wirex.com>
Subject: Re: [rsbac] Thoughts on the "No Linux Security Modules framework" old claims
Date: Fri, 25 Feb 2005 11:14:24 +0100	[thread overview]
Message-ID: <20050225101423.GG19066@tpkurt.garloff.de> (raw)
In-Reply-To: <200502240928.46262.ao@rsbac.org>

[-- Attachment #1: Type: text/plain, Size: 1392 bytes --]

Hi Amon,

On Thu, Feb 24, 2005 at 09:28:38AM +0100, Amon Ott wrote:
> On Donnerstag 24 Februar 2005 01:55, Kurt Garloff wrote:
> > If you apply them (and I hope Linus will), capabilities is default
> > and you can replace that by loading an LSM. You can stack capability
> > on top of the primary LSM again, if the latter supports this.
> 
> Well, not quite, although it is an improvement.
> 
> As long as the capabilities module does not support stacking, anybody 
> needing capabilities and e.g. on-access scanning with Dazuko will 
> have to unload this module, load another module, and reload it. 

Nope.

With the patchset applied you get capabilities as default behaviour,
so with_out_ any LSM loaded.

> This creates a nasty race condition. 

You can load any module to replace capabilities. No race condition
(except that the point in time when the security_ops is actually
 updated is not well defined as there's no locking nor wmb()).

You can also load the capabilities module on top of the default,
but it won't change any behaviour then (other than eating a few
percent performance in some paths).

> BTW, what happens if capabilities 
> have been compiled static, not as a module?

Why would you want to do this?

> AFAIK, not all LSM modules provide correct stacking. 

True.

Regards,
-- 
Kurt Garloff, Director SUSE Labs, Novell Inc.

[-- Attachment #2: Type: application/pgp-signature, Size: 189 bytes --]

  reply	other threads:[~2005-02-25 10:14 UTC|newest]

Thread overview: 20+ messages / expand[flat|nested]  mbox.gz  Atom feed  top
2005-02-15 22:38 Lorenzo Hernández García-Hierro
2005-02-16  4:21 ` Valdis.Kletnieks
2005-02-16 13:29   ` Lorenzo Hernández García-Hierro
2005-02-16 13:30     ` Stephen Smalley
2005-02-16 16:07     ` Casey Schaufler
2005-02-16 15:52   ` Casey Schaufler
2005-02-16 17:41     ` Valdis.Kletnieks
2005-02-21 10:19 ` [rsbac] " Amon Ott
2005-02-21 17:15   ` Lorenzo Hernández García-Hierro
2005-02-21 17:50     ` Casey Schaufler
2005-02-22  8:57       ` Amon Ott
2005-02-22 15:23         ` Casey Schaufler
2005-02-24  0:55   ` Kurt Garloff
2005-02-24  8:28     ` Amon Ott
2005-02-25 10:14       ` Kurt Garloff [this message]
2005-02-23 21:37 ` Crispin Cowan
2005-02-23 22:00   ` Lorenzo Hernández García-Hierro
2005-02-23 22:07     ` Crispin Cowan
2005-02-23 22:34       ` Lorenzo Hernández García-Hierro
2005-02-24 13:23   ` Stephen Smalley

Reply instructions:

You may reply publicly to this message via plain-text email
using any one of the following methods:

* Save the following mbox file, import it into your mail client,
  and reply-to-all from there: mbox

  Avoid top-posting and favor interleaved quoting:
  https://en.wikipedia.org/wiki/Posting_style#Interleaved_style

* Reply using the --to, --cc, and --in-reply-to
  switches of git-send-email(1):

  git send-email \
    --in-reply-to=20050225101423.GG19066@tpkurt.garloff.de \
    --to=garloff@suse.de \
    --cc=ao@rsbac.org \
    --cc=linux-kernel@vger.kernel.org \
    --cc=linux-security-module@wirex.com \
    --cc=lorenzo@gnu.org \
    --cc=rsbac@rsbac.org \
    /path/to/YOUR_REPLY

  https://kernel.org/pub/software/scm/git/docs/git-send-email.html

* If your mail client supports setting the In-Reply-To header
  via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox

all inboxes | Powered by JetHome®