Return-Path: Received: (majordomo@vger.kernel.org) by vger.kernel.org via listexpand id S1030816AbbDWTaW (ORCPT ); Thu, 23 Apr 2015 15:30:22 -0400 Received: from mail.linuxfoundation.org ([140.211.169.12]:34644 "EHLO mail.linuxfoundation.org" rhost-flags-OK-OK-OK-OK) by vger.kernel.org with ESMTP id S1030357AbbDWTaT (ORCPT ); Thu, 23 Apr 2015 15:30:19 -0400 Date: Thu, 23 Apr 2015 21:30:13 +0200 From: Greg Kroah-Hartman To: Stephen Smalley , Karol Lewandowski Cc: Andy Lutomirski , Linus Torvalds , Andrew Morton , Arnd Bergmann , "Eric W. Biederman" , One Thousand Gnomes , Tom Gundersen , Jiri Kosina , "linux-kernel@vger.kernel.org" , Daniel Mack , David Herrmann , Djalal Harouni Subject: Re: [GIT PULL] kdbus for 4.1-rc1 Message-ID: <20150423193013.GA14365@kroah.com> References: <20150413190350.GA9485@kroah.com> <20150423130548.GA4253@kroah.com> <20150423163616.GA10874@kroah.com> <20150423171640.GA11227@kroah.com> <55392F01.1090307@tycho.nsa.gov> MIME-Version: 1.0 Content-Type: text/plain; charset=us-ascii Content-Disposition: inline In-Reply-To: <55392F01.1090307@tycho.nsa.gov> User-Agent: Mutt/1.5.23 (2014-03-12) Sender: linux-kernel-owner@vger.kernel.org List-ID: X-Mailing-List: linux-kernel@vger.kernel.org Content-Length: 1441 Lines: 32 On Thu, Apr 23, 2015 at 01:42:25PM -0400, Stephen Smalley wrote: > On 04/23/2015 01:16 PM, Greg Kroah-Hartman wrote: > > The binder developers at Samsung have stated that the implementation we > > have here works for their model as well, so I guess that is some kind of > > verification it's not entirely tied to D-Bus. They have plans on > > dropping the existing binder kernel code and using the kdbus code > > instead when it is merged. > > Where do things stand wrt LSM hooks for kdbus? I don't see any security > hook calls in the kdbus tree except for the purpose of metadata > collection of process security labels. But nothing for enforcing MAC > over kdbus IPC. binder has a set of security hooks for that purpose, so > it would be a regression wrt MAC enforcement to switch from binder to > kdbus without equivalent checking there. There was a set of LSM hooks proposed for kdbus posted by Karol Lewandowsk last October, and it also included SELinux and Smack patches. They were going to be refreshed based on the latest code changes, but I haven't seen them posted, or I can't seem to find them in my limited email archive. Karol, what's the status of them? thanks, greg k-h -- To unsubscribe from this list: send the line "unsubscribe linux-kernel" in the body of a message to majordomo@vger.kernel.org More majordomo info at http://vger.kernel.org/majordomo-info.html Please read the FAQ at http://www.tux.org/lkml/