Groups | Search | Server Info | Keyboard shortcuts | Login | Register [http] [https] [nntp] [nntps]


Groups > linux.kernel > #1620674

Re: [PATCH RFC v2 2/3] security: add the ModAutoRestrict Linux Security Module

Path csiph.com!eternal-september.org!feeder.eternal-september.org!news.unit0.net!news.panservice.it!diesel.cu.mi.it!bofh.it!news.nic.it!robomod
From Djalal Harouni <tixxdz@gmail.com>
Newsgroups linux.kernel
Subject Re: [PATCH RFC v2 2/3] security: add the ModAutoRestrict Linux Security Module
Date Mon, 10 Apr 2017 22:00:02 +0200
Message-ID <tuNDI-5ev-17@gated-at.bofh.it> (permalink)
References <tuizT-1Fl-5@gated-at.bofh.it> <tuizT-1Fl-3@gated-at.bofh.it> <tuJJO-2yX-71@gated-at.bofh.it> <tuMeB-4oO-7@gated-at.bofh.it> <tuMRk-4S4-29@gated-at.bofh.it>
X-Original-To Casey Schaufler <casey@schaufler-ca.com>
Dkim-Signature v=1; a=rsa-sha256; c=relaxed/relaxed; d=gmail.com; s=20161025; h=mime-version:in-reply-to:references:from:date:message-id:subject:to :cc; bh=txoMuGaIsei7+7Ptaiwgynd1GcP7DIcTat7m0ObWUH8=; b=ZLix9ISDJRqCrKw7o+TrbnB5VXP/QNX/Z7K+PjW97UALb96aXN1ilBBELOlotbeqRj dfkBAFqqvOn0ExDj0q6oSsDz2fLtTVc1E5J8XuhOhHTqMXCqdnax2hzSRLVeWv3RCYbM mi2rn+QLV0ZZUUaBCDaOqipy6Y3GcvNdpj/qdx69EEPVToIlUQN7lFUq85VhazrUUjXP oB8Rrzn6bBB/yT7bEH2hykISKhNZ19j5BtQGUeWDjIhNJK0Sd651B1cOZklt1DAHAgzP HJIB1Cv8wpdnS/eIKkzsl4Gm6vUfg4OO4GPcvax83iBUScKBa7i2kD9djZrm/wi3rWIL sFQA==
X-Google-Dkim-Signature v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20161025; h=x-gm-message-state:mime-version:in-reply-to:references:from:date :message-id:subject:to:cc; bh=txoMuGaIsei7+7Ptaiwgynd1GcP7DIcTat7m0ObWUH8=; b=Q4UxGT6w5uC93AJFoOu3H+w8VVQ1klK80A1csvzTU2Ftxfqhk3s8G8QlS1VGH1dbI8 qwq0dBdEtI/DmbWMDVpgNe8RSO7GmpJ7bwUEnJUc5Nc1LFiGVZp+s/MvrH2qH+yB2/e8 iAPn48frfqnSwPt1H/p/Bp+oFa99vwFCsaWGT/uWGu959GEApQAwPLkPmXXZEUXeTp4s H0N/YBgFQeCtEIAJid4RnCeEyCpaujAnkpwNNOWmdB7umWeQH9W6TQT/eTECrLUIqB3h hODSseJeOVS3yRasmR1eTkSRf+OnRzVX7oD9AwS/6x+65EsRFZZ2PK7E/FrIvIJkyubU vFmA==
X-Gm-Message-State AN3rC/6Wzht3PKC/RBqMOzdp64beY7nQNu8MneHyqhmW/I7fvOLS69+HqQaZF+2xbcCGSAZRAR0h9BI704NFWQ==
X-Received by 10.237.63.37 with SMTP id p34mr12124114qtf.94.1491854154692; Mon, 10 Apr 2017 12:55:54 -0700 (PDT)
MIME-Version 1.0
Content-Type text/plain; charset=UTF-8
Sender robomod@news.nic.it
List-ID <linux-kernel.vger.kernel.org>
X-Mailing-List linux-kernel@vger.kernel.org
Approved robomod@news.nic.it
Lines 35
Organization linux.* mail to news gateway
X-Original-Cc Linux Kernel Mailing List <linux-kernel@vger.kernel.org>, Andy Lutomirski <luto@kernel.org>, Kees Cook <keescook@chromium.org>, Andrew Morton <akpm@linux-foundation.org>, kernel-hardening@lists.openwall.com, LSM List <linux-security-module@vger.kernel.org>, Linux API <linux-api@vger.kernel.org>, Dongsu Park <dpark@posteo.net>, James Morris <james.l.morris@oracle.com>, "Serge E. Hallyn" <serge@hallyn.com>, Paul Moore <paul@paul-moore.com>, Tetsuo Handa <penguin-kernel@i-love.sakura.ne.jp>, Greg Kroah-Hartman <gregkh@linuxfoundation.org>
X-Original-Date Mon, 10 Apr 2017 21:55:54 +0200
X-Original-Message-ID <CAEiveUcKNY1p7w2drFpqtvumC6Xw-2W0QXr7Q4YW1dwtwYdnzQ@mail.gmail.com>
X-Original-References <1491734530-25002-1-git-send-email-tixxdz@gmail.com> <1491734530-25002-3-git-send-email-tixxdz@gmail.com> <b483ccc8-406c-a620-9f7a-fdcbbc3fdb26@schaufler-ca.com> <CAEiveUeYB8jQoP9R9xSj+5dxc3cfCg46Z=C5TkfkYibDWrEbPQ@mail.gmail.com> <36b005c9-e550-2ee8-61b2-136628f1a05f@schaufler-ca.com>
X-Original-Sender linux-kernel-owner@vger.kernel.org
Xref csiph.com linux.kernel:1620674

Show key headers only | View raw


On Mon, Apr 10, 2017 at 9:04 PM, Casey Schaufler <casey@schaufler-ca.com> wrote:
> On 4/10/2017 11:27 AM, Djalal Harouni wrote:
>> On Mon, Apr 10, 2017 at 5:42 PM, Casey Schaufler <casey@schaufler-ca.com> wrote:
>>> On 4/9/2017 3:42 AM, Djalal Harouni wrote:
[...]

>>>> --- a/security/security.c
>>>> +++ b/security/security.c
>>>> @@ -70,6 +70,7 @@ int __init security_init(void)
>>>>       capability_add_hooks();
>>>>       yama_add_hooks();
>>>>       loadpin_add_hooks();
>>>> +     modautorestrict_init();
>>> This should be modautorestrict_add_hooks() if this were
>>> a "minor" module, but as it's using a blob it is a "major"
>>> module. Either way, this is not right.
>> Do you mean that if I'm using a blob, it should go with the rest LSMs
>> in do_security_initcalls() ?
>
> Right. Today you have coincidental non-interference because
> no one else is using the task blob. As you're aware, TOMOYO
> is going to start using it, and I believe the AppArmor has
> plans for it as well. There are parts of the Smack cred blob
> that should probably go in the task blob as they aren't used
> in access decisions. I haven't looked closely enough, but that's
> possible for SELinux, too. So even though it's a new blob, the
> major/minor rules apply.
>

Ok, point taken.

Thanks!

-- 
tixxdz

Back to linux.kernel | Previous | Next — Previous in thread | Find similar | Unroll thread


Thread

Re: [PATCH RFC v2 2/3] security: add the ModAutoRestrict Linux  Security Module Casey Schaufler <casey@schaufler-ca.com> - 2017-04-10 17:50 +0200
  Re: [PATCH RFC v2 2/3] security: add the ModAutoRestrict Linux  Security Module Djalal Harouni <tixxdz@gmail.com> - 2017-04-10 20:30 +0200
    Re: [PATCH RFC v2 2/3] security: add the ModAutoRestrict Linux  Security Module Casey Schaufler <casey@schaufler-ca.com> - 2017-04-10 21:10 +0200
      Re: [PATCH RFC v2 2/3] security: add the ModAutoRestrict Linux  Security Module Djalal Harouni <tixxdz@gmail.com> - 2017-04-10 22:00 +0200

csiph-web