Groups | Search | Server Info | Keyboard shortcuts | Login | Register [http] [https] [nntp] [nntps]
Groups > linux.kernel > #1696748
| From | "Serge E. Hallyn" <serge@hallyn.com> |
|---|---|
| Newsgroups | linux.kernel |
| Subject | Re: [PATCH v2] xattr: Enable security.capability in user namespaces |
| Date | 2017-07-26 05:10 +0200 |
| Message-ID | <u7kRX-3fc-1@gated-at.bofh.it> (permalink) |
| References | (5 earlier) <u38Z4-44P-37@gated-at.bofh.it> <u3aHw-5hS-7@gated-at.bofh.it> <u3cJl-6Ez-23@gated-at.bofh.it> <u3erM-7Qa-13@gated-at.bofh.it> <u3erM-7Qa-11@gated-at.bofh.it> |
| Organization | linux.* mail to news gateway |
On Fri, Jul 14, 2017 at 03:26:14PM -0400, Mimi Zohar wrote: > On Fri, 2017-07-14 at 13:17 -0500, Eric W. Biederman wrote: > > Which brings us to the semantic question of would it be nice to have > > stacked IMA/EVM on the same file. > > > > I really don't think we do. I think allowing multiple keys for > > different part of trusting files is easy enough that we should have no > > need to fight over which keys do which. > > We definitely want to support different policies on the native and in > the namespace with different keys and keyrings. Ok, so Stefan's code to support userspace in a container reading security.ima and getting back the value for security.ima@uid=1000 (if 1000 is the kuid of the container's root user) is in fact useful to IMA?
Back to linux.kernel | Previous | Next — Next in thread | Find similar | Unroll thread
Re: [PATCH v2] xattr: Enable security.capability in user namespaces "Serge E. Hallyn" <serge@hallyn.com> - 2017-07-26 05:10 +0200 Re: [PATCH v2] xattr: Enable security.capability in user namespaces Mimi Zohar <zohar@linux.vnet.ibm.com> - 2017-07-26 16:00 +0200
csiph-web