From: "Serge E. Hallyn" <serue@us.ibm.com>
To: Mimi Zohar <zohar@us.ibm.com>
Cc: Daniel Walker <dwalker@mvista.com>,
akpm@osdl.org, kjhall@linux.vnet.ibm.com,
linux-kernel@vger.kernel.org,
Stephen Smalley <sds@epoch.ncsc.mil>
Subject: Re: Should be [PATCH -mm] -- Re: [PATCH -rt] panic on SLIM + selinux
Date: Tue, 2 Jan 2007 15:40:27 -0600 [thread overview]
Message-ID: <20070102214026.GA13887@sergelap.austin.ibm.com> (raw)
In-Reply-To: <OF9AB42A1E.A7654F8F-ON85257257.0061FF6C-85257257.00642493@us.ibm.com>
Quoting Mimi Zohar (zohar@us.ibm.com):
> Being able to compile both SELinux and SLIM into the kernel was done
> intentionally.
Intentionally so that you can switch back and forth for testing?
> The kernel parameters 'selinux' and 'slim' can enable
> or disable the LSM module at boot. Perhaps, for the time being, the
> SECURITY_SLIM_BOOTPARAM_VALUE should default to 0.
That should solve the problem for most people. People wanting to
test with slim will still have to specify 'selinux=0' or get the
boot failure. But I suspect that having selinux automatically
not load when slim is loaded will be considered too unsafe?
Mimi, what about moving slim down below selinux in the Makefile,
and having slim refuse to load if security_ops is not an _ops you
know about (i.e. dummy_ops or capability_ops)? Then you can leave
SECURITY_SLIM_BOOTPARAM_VALUE as 1, and users just have to say
'selinux=0' to boot slim? Just a thought, maybe less intuitive...
-serge
prev parent reply other threads:[~2007-01-02 21:40 UTC|newest]
Thread overview: 5+ messages / expand[flat|nested] mbox.gz Atom feed top
2006-12-30 15:48 Daniel Walker
2006-12-30 15:53 ` Should be [PATCH -mm] -- " Daniel Walker
2007-01-02 18:05 ` Mimi Zohar
2007-01-02 19:01 ` Daniel Walker
2007-01-02 21:40 ` Serge E. Hallyn [this message]
Reply instructions:
You may reply publicly to this message via plain-text email
using any one of the following methods:
* Save the following mbox file, import it into your mail client,
and reply-to-all from there: mbox
Avoid top-posting and favor interleaved quoting:
https://en.wikipedia.org/wiki/Posting_style#Interleaved_style
* Reply using the --to, --cc, and --in-reply-to
switches of git-send-email(1):
git send-email \
--in-reply-to=20070102214026.GA13887@sergelap.austin.ibm.com \
--to=serue@us.ibm.com \
--cc=akpm@osdl.org \
--cc=dwalker@mvista.com \
--cc=kjhall@linux.vnet.ibm.com \
--cc=linux-kernel@vger.kernel.org \
--cc=sds@epoch.ncsc.mil \
--cc=zohar@us.ibm.com \
/path/to/YOUR_REPLY
https://kernel.org/pub/software/scm/git/docs/git-send-email.html
* If your mail client supports setting the In-Reply-To header
via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line
before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox
all inboxes | Powered by JetHome®