Re: [PATCH net-next v6 00/11] Landlock LSM: Toward unprivileged sandboxing

2017-04-18 Thread Mickaël Salaün
On 19/04/2017 01:26, Kees Cook wrote: > On Tue, Mar 28, 2017 at 4:46 PM, Mickaël Salaün wrote: >> This sixth series add some changes to the previous one [1], including a >> simpler >> rule inheritance hierarchy (similar to seccomp-bpf), a ptrace scope >> protection, >> some

Re: [PATCH net-next v6 00/11] Landlock LSM: Toward unprivileged sandboxing

2017-04-18 Thread Mickaël Salaün
On 19/04/2017 01:26, Kees Cook wrote: > On Tue, Mar 28, 2017 at 4:46 PM, Mickaël Salaün wrote: >> This sixth series add some changes to the previous one [1], including a >> simpler >> rule inheritance hierarchy (similar to seccomp-bpf), a ptrace scope >> protection, >> some file renaming

Re: [PATCH net-next v6 00/11] Landlock LSM: Toward unprivileged sandboxing

2017-04-18 Thread Kees Cook
On Tue, Mar 28, 2017 at 4:46 PM, Mickaël Salaün wrote: > This sixth series add some changes to the previous one [1], including a > simpler > rule inheritance hierarchy (similar to seccomp-bpf), a ptrace scope > protection, > some file renaming (better feature identification

Re: [PATCH net-next v6 00/11] Landlock LSM: Toward unprivileged sandboxing

2017-04-18 Thread Kees Cook
On Tue, Mar 28, 2017 at 4:46 PM, Mickaël Salaün wrote: > This sixth series add some changes to the previous one [1], including a > simpler > rule inheritance hierarchy (similar to seccomp-bpf), a ptrace scope > protection, > some file renaming (better feature identification per file), a

[PATCH net-next v6 00/11] Landlock LSM: Toward unprivileged sandboxing

2017-03-28 Thread Mickaël Salaün
Hi, This sixth series add some changes to the previous one [1], including a simpler rule inheritance hierarchy (similar to seccomp-bpf), a ptrace scope protection, some file renaming (better feature identification per file), a future-proof eBPF subtype and miscellaneous cosmetic fixes. This is

[PATCH net-next v6 00/11] Landlock LSM: Toward unprivileged sandboxing

2017-03-28 Thread Mickaël Salaün
Hi, This sixth series add some changes to the previous one [1], including a simpler rule inheritance hierarchy (similar to seccomp-bpf), a ptrace scope protection, some file renaming (better feature identification per file), a future-proof eBPF subtype and miscellaneous cosmetic fixes. This is