[PATCH v5 00/10] Landlock LSM: Toward unprivileged sandboxing

2017-02-21 Thread Mickaël Salaün
Hi, This series follows 4 previous RFCs [1]. This is the first step of the roadmap discussed at LPC [2] (with the inheritance feature included). The big change is an abstraction over LSM hooks. Instead of exposing a similar interface to userland, Landlock wraps LSM hooks into Landlock events.

[PATCH v5 00/10] Landlock LSM: Toward unprivileged sandboxing

2017-02-21 Thread Mickaël Salaün
Hi, This series follows 4 previous RFCs [1]. This is the first step of the roadmap discussed at LPC [2] (with the inheritance feature included). The big change is an abstraction over LSM hooks. Instead of exposing a similar interface to userland, Landlock wraps LSM hooks into Landlock events.