Re: [RFC PATCH] Adding prctl override support for LSMs

2008-01-11 Thread Stephen Smalley
On Wed, 2008-01-09 at 20:52 -0800, Andrew Morgan wrote: -BEGIN PGP SIGNED MESSAGE- Hash: SHA1 [Replying to everyone at once.] Yes, this is how I wanted to implement the per-process securebits thing. This is also half of my original patch (from last year). The recent cap_bset

Re: [TOMOYO #6 retry 08/21] Utility functions and policy manipulationinterface.

2008-01-11 Thread James Morris
On Sat, 12 Jan 2008, Tetsuo Handa wrote: Hello. James Morris wrote: TOMOYO Linux uses /sys/kernel/security/tomoyo interface for configuration. Why aren't you using securityfs for this? (It was designed for LSMs). Doh, it is using securityfs, don't worry. I got a

Re: [TOMOYO #6 retry 08/21] Utility functions and policy manipulationinterface.

2008-01-11 Thread Greg KH
On Sat, Jan 12, 2008 at 11:06:17AM +0900, Tetsuo Handa wrote: Hello. James Morris wrote: TOMOYO Linux uses /sys/kernel/security/tomoyo interface for configuration. Why aren't you using securityfs for this? (It was designed for LSMs). Doh, it is using securityfs, don't

Re: [TOMOYO #6 retry 08/21] Utility functions and policymanipulationinterface.

2008-01-11 Thread Tetsuo Handa
Hello. Greg KH wrote: If sysfs becomes not available at /sys/ , where securityfs is going to be mounted? sysfs is not going away any time soon, don't worry :) I see. Thanks. - To unsubscribe from this list: send the line unsubscribe linux-security-module in the body of a message to