Re: [PATCH v1] security: Add a new hook: inode_touch_atime
From: Al Viro
Date: Wed Dec 21 2016 - 19:57:42 EST
On Thu, Dec 22, 2016 at 01:01:39AM +0100, Mickaël Salaün wrote:
> SELinux should be interested. This is useful to create sandboxes so
> other LSM may be interested too
>
> I'm working on a new LSM and I would like this kind of hook to create a
> real read-only environment.
What the...? Have you noticed
if (!sb_start_write_trylock(inode->i_sb))
return;
if (__mnt_want_write(mnt) != 0)
goto skip_update;
in touch_atime()? Just mount them read-only in your sandbox (on either
level - both per-mountpoint and per-fs r/o will do) and be done
with that; why bother with LSM when regular tools would suffice?