Home
Reading
Searching
Subscribe
Sponsors
Statistics
Posting
Contact
Spam
Lists
Links
About
Hosting
Filtering
Features Download
Marketing
Archives
FAQ
Blog
 
Gmane
From: James Morris <jmorris <at> namei.org>
Subject: Re: [PATCH] ptrace: allow restriction of ptrace scope
Newsgroups: gmane.linux.kernel.lsm
Date: Monday 21st June 2010 00:52:11 UTC (over 7 years ago)
On Fri, 18 Jun 2010, Theodore Tso wrote:

> Yet I would really like a number of features such as this ptrace scope
idea ---
> which I think is a useful feature, and it may be that stacking is the
only
> way we can resolve this debate.

We've already reached a consensus that these things should be put into a 
separate LSM so we can evaluate the possible need for some form of 
stacking or a security library API.

Note that people using SELinux or AppArmor already have the ability to 
restrict ptrace, and they would thus not need to stack this function if it 
were in a separate LSM.

Do you have a use-case where stacking would be useful here?



- James
-- 
James Morris

--
To unsubscribe from this list: send the line "unsubscribe
linux-security-module" in
the body of a message to [email protected]
More majordomo info at  http://vger.kernel.org/majordomo-info.html
 
CD: 3ms