From mboxrd@z Thu Jan 1 00:00:00 1970 Return-Path: Received: (majordomo@vger.kernel.org) by vger.kernel.org via listexpand id S1756158Ab0BEMbj (ORCPT ); Fri, 5 Feb 2010 07:31:39 -0500 Received: from ixro-out-rtc.ixiacom.com ([92.87.192.98]:11565 "EHLO ixro-ex1.ixiacom.com" rhost-flags-OK-OK-OK-FAIL) by vger.kernel.org with ESMTP id S1755706Ab0BEMbh (ORCPT ); Fri, 5 Feb 2010 07:31:37 -0500 From: Octavian Purdila Organization: Ixia To: Cong Wang Subject: Re: [RFC Patch] net: reserve ports for applications using fixed port numbers Date: Fri, 5 Feb 2010 14:28:12 +0200 User-Agent: KMail/1.12.2 (Linux/2.6.32-trunk-686; KDE/4.3.2; i686; ; ) Cc: Tetsuo Handa , davem@davemloft.net, linux-kernel@vger.kernel.org, eric.dumazet@gmail.com, linux-rdma@vger.kernel.org, netdev@vger.kernel.org, nhorman@tuxdriver.com, linux-sctp@vger.kernel.org References: <20100204.094110.64247447.davem@davemloft.net> <201002050305.22227.opurdila@ixiacom.com> <4B6BB447.8080806@redhat.com> In-Reply-To: <4B6BB447.8080806@redhat.com> MIME-Version: 1.0 Content-Type: Text/Plain; charset="us-ascii" Content-Transfer-Encoding: 7bit Message-Id: <201002051428.12767.opurdila@ixiacom.com> X-OriginalArrivalTime: 05 Feb 2010 12:31:35.0328 (UTC) FILETIME=[27CC3A00:01CAA65F] Sender: linux-kernel-owner@vger.kernel.org List-ID: X-Mailing-List: linux-kernel@vger.kernel.org On Friday 05 February 2010 08:01:43 you wrote: > >> If you can accept his version, I want to use his version (with an > >> interface for updating above "reserved_ports" by not only root user's > >> sysctl() but also MAC's policy configuration). > > > > I think that simply using an interface to update the reserved_ports from > > MAC policy configuration module wouldn't work, as root will be able to > > modify the policy via sysctl. > > > > I think that we might need to: > > > > a) have a reserved_port updater > > > > b) put a LSM hook into that > > > > c) use the reserved_port updater from sysctl > > Ideally, you'd provide an interface for port allocator to use, so > doing port reservation will be easier. > If I understand the TOMOYO requirements correctly, we need a way to restrict a user action based on some security policy (in this case the ability to clear reserved ports). Traditionally that has been done with LSM hooks, so I think that approach is preferable.