Re: [PATCH] LSM: ModPin LSM for module loading restrictions

From: Tetsuo Handa
Date: Wed Oct 16 2013 - 20:37:27 EST


Kees Cook wrote:
> So I sent this LSM as one I\'d been waiting
> for stacking on. Essentially, I\'m breaking the catch-22 by sending
> this. I\'d like it to get into the tree so we don\'t have a catch-22
> about stacking any more. :)

I\'m also trying to break the catch-22 by sending KPortReserve.
I would send another one which uses only security_file_alloc/free .

> The core changes first, and the userspace interface changes next?

I welcome that approach, for none of such single function LSM modules
depends on userspace interface changes.
--
To unsubscribe from this list: send the line "unsubscribe linux-kernel" in
the body of a message to majordomo@xxxxxxxxxxxxxxx
More majordomo info at http://vger.kernel.org/majordomo-info.html
Please read the FAQ at http://www.tux.org/lkml/