Groups | Search | Server Info | Keyboard shortcuts | Login | Register [http] [https] [nntp] [nntps]
Groups > linux.kernel > #1574641
| From | Djalal Harouni <tixxdz@gmail.com> |
|---|---|
| Newsgroups | linux.kernel |
| Subject | Re: [RFC/PATCH 1/3] security: add the security_task_copy() hook |
| Date | 2017-02-06 13:50 +0100 |
| Message-ID | <t7QU2-4ZM-11@gated-at.bofh.it> (permalink) |
| References | <t6t3r-6OU-15@gated-at.bofh.it> <t6t3r-6OU-13@gated-at.bofh.it> <t7PbA-3SX-19@gated-at.bofh.it> |
| Organization | linux.* mail to news gateway |
Hi Tetsuo, On Mon, Feb 6, 2017 at 11:49 AM, Tetsuo Handa <penguin-kernel@i-love.sakura.ne.jp> wrote: > Djalal Harouni wrote: >> To achieve the above we add the security_task_copy() hook that allows us >> to clone the Timgad context of parent into child task_struct. >> >> The security hook can also be used by new LSMs after the child task has >> done some initialization, this way they won't clash with the major LSMs. >> The situation is not really well, this hook allows us to introduce a >> stackable LSM that can be easily used with all other LSMs. > > We are already planning to revive security_task_alloc() hook (probably in Linux 4.12) > ( news://news.gmane.org:119/201701101958.JAD43709.OtJSOQFVFOLHMF@I-love.SAKURA.ne.jp ). > Is security_task_alloc() called too early for your case? Hmm, didn't know about it, thank you! Yes that seems the same, to have a per-task vars or context. I'm reading http://www.spinics.net/linux/fedora/linux-security-module/msg17004.html For my specific use case I'm still not sure. I was thinking that since this is LSM maybe it would be useful to only add one hook after all the copy_*() functions that also copy the context, maybe another LSM will find it useful and may want to check the context of namespaces, fs (copy_namespaces(), copy_fs() ...). I mean this already happened to me with security_task_create() which is too early, so maybe try to do it right. The other thing is cgroups cgroup_can_fork() better do it after which avoids me to clean up. IMHO the best place is near or after copy_seccomp() where we hold the lock, especially if there is an LSM that wants to copy/apply the context on all other threads not only current. Ultimately if we are copying stuff then maybe it should happen as late as possible, and if we have to sleep I guess we can use security_task_create() to allocate ? What do you think ? Thanks! > (Well, we want to configure http archive like marc.info ?) -- tixxdz
Back to linux.kernel | Previous | Next — Previous in thread | Next in thread | Find similar | Unroll thread
[RFC/PATCH 1/3] security: add the security_task_copy() hook Djalal Harouni <tixxdz@gmail.com> - 2017-02-02 18:10 +0100
Re: [RFC/PATCH 1/3] security: add the security_task_copy() hook Tetsuo Handa <penguin-kernel@I-love.SAKURA.ne.jp> - 2017-02-06 12:00 +0100
Re: [RFC/PATCH 1/3] security: add the security_task_copy() hook Djalal Harouni <tixxdz@gmail.com> - 2017-02-06 13:50 +0100
Re: [RFC/PATCH 1/3] security: add the security_task_copy() hook Djalal Harouni <tixxdz@gmail.com> - 2017-02-06 14:20 +0100
csiph-web