Re: [PATCH 2/3] kexec: call LSM hook for kexec_load syscall

2018-05-03 Thread Eric W. Biederman
Mimi Zohar writes: > On Thu, 2018-05-03 at 11:42 -0500, Eric W. Biederman wrote: >> Casey Schaufler writes: >> >> > On 5/3/2018 8:51 AM, Eric W. Biederman wrote: >> >> Mimi Zohar writes: >> >> >> >>> On Wed,

Re: [PATCH 2/3] kexec: call LSM hook for kexec_load syscall

2018-05-03 Thread Mimi Zohar
On Thu, 2018-05-03 at 11:42 -0500, Eric W. Biederman wrote: > Casey Schaufler writes: > > > On 5/3/2018 8:51 AM, Eric W. Biederman wrote: > >> Mimi Zohar writes: > >> > >>> On Wed, 2018-05-02 at 09:45 -0500, Eric W. Biederman wrote: > Mimi

Re: [PATCH 2/3] kexec: call LSM hook for kexec_load syscall

2018-05-03 Thread Eric W. Biederman
Casey Schaufler writes: > On 5/3/2018 8:51 AM, Eric W. Biederman wrote: >> Mimi Zohar writes: >> >>> On Wed, 2018-05-02 at 09:45 -0500, Eric W. Biederman wrote: Mimi Zohar writes: > Allow LSMs and IMA to

Re: [PATCH 2/3] kexec: call LSM hook for kexec_load syscall

2018-05-03 Thread Casey Schaufler
On 5/3/2018 8:51 AM, Eric W. Biederman wrote: > Mimi Zohar writes: > >> On Wed, 2018-05-02 at 09:45 -0500, Eric W. Biederman wrote: >>> Mimi Zohar writes: >>> Allow LSMs and IMA to differentiate between the kexec_load and

Re: [PATCH 2/3] kexec: call LSM hook for kexec_load syscall

2018-05-03 Thread Eric W. Biederman
Mimi Zohar writes: > On Wed, 2018-05-02 at 09:45 -0500, Eric W. Biederman wrote: >> Mimi Zohar writes: >> >> > Allow LSMs and IMA to differentiate between the kexec_load and >> > kexec_file_load syscalls by adding an "unnecessary" call to >>

Re: [PATCH 2/3] kexec: call LSM hook for kexec_load syscall

2018-05-02 Thread Mimi Zohar
On Wed, 2018-05-02 at 09:45 -0500, Eric W. Biederman wrote: > Mimi Zohar writes: > > > Allow LSMs and IMA to differentiate between the kexec_load and > > kexec_file_load syscalls by adding an "unnecessary" call to > > security_kernel_read_file() in kexec_load. This

Re: [PATCH 2/3] kexec: call LSM hook for kexec_load syscall

2018-05-02 Thread Eric W. Biederman
Mimi Zohar writes: > Allow LSMs and IMA to differentiate between the kexec_load and > kexec_file_load syscalls by adding an "unnecessary" call to > security_kernel_read_file() in kexec_load. This would be similar to the > existing init_module syscall calling

Re: [PATCH 2/3] kexec: call LSM hook for kexec_load syscall

2018-05-02 Thread Mimi Zohar
Hi Eric, I'd really appreciate your reviewing/ack'ing this patch. thanks, Mimi On Thu, 2018-04-12 at 18:41 -0400, Mimi Zohar wrote: > Allow LSMs and IMA to differentiate between the kexec_load and > kexec_file_load syscalls by adding an "unnecessary" call to > security_kernel_read_file() in