Re: [TOMOYO #7 30/30] Hooks for SAKURA and TOMOYO.

From: Paul Moore
Date: Mon Apr 07 2008 - 11:41:23 EST


On Friday 04 April 2008 8:23:12 am Tetsuo Handa wrote:
> This file contains modifications against kernel source code
> needed to use TOMOYO Linux 1.6.
>
> Although LSM hooks are provided for performing access control,
> TOMOYO Linux 1.6 doesn't use LSM because of the following reasons.

Hello,

I understand your frustration with the existing LSM hooks/API and your
reasoning for abandoning LSM in favor of a new set of hooks, however, I
think this sets a dangerous precedence which could result in an
abundance of security related hooks scattered throughout the kernel. I
would much rather see the LSM API extended/tweaked to support the needs
of SAKURA and TOMOYO than ignored and duplicated; I suspect several
others will say the same.

You have made good progress with TOMOYO so far and if I can remember
correctly you really only have one hurdle left, the VFS portion.
Please continue to seek a solution to this that fits within the LSM
framework.

Thank you.

--
paul moore
linux @ hp
--
To unsubscribe from this list: send the line "unsubscribe linux-kernel" in
the body of a message to majordomo@xxxxxxxxxxxxxxx
More majordomo info at http://vger.kernel.org/majordomo-info.html
Please read the FAQ at http://www.tux.org/lkml/