Return-Path: Received: (majordomo@vger.kernel.org) by vger.kernel.org via listexpand id S1756020AbXJAU2c (ORCPT ); Mon, 1 Oct 2007 16:28:32 -0400 Received: (majordomo@vger.kernel.org) by vger.kernel.org id S1752730AbXJAU2X (ORCPT ); Mon, 1 Oct 2007 16:28:23 -0400 Received: from web36609.mail.mud.yahoo.com ([209.191.85.26]:22971 "HELO web36609.mail.mud.yahoo.com" rhost-flags-OK-OK-OK-OK) by vger.kernel.org with SMTP id S1752222AbXJAU2W (ORCPT ); Mon, 1 Oct 2007 16:28:22 -0400 X-YMail-OSG: BHsv0JYVM1ljlrS8UGs9LJiKotl8x6xBc.Odz8i.y0_WpPToiDGnXLFcNOUKxZj7oXusBxxNYA-- X-RocketYMMF: rancidfat Date: Mon, 1 Oct 2007 13:28:21 -0700 (PDT) From: Casey Schaufler Reply-To: casey@schaufler-ca.com Subject: Re: [PATCH] Version 3 (2.6.23-rc8) Smack: Simplified Mandatory Access Control Kernel To: Andi Kleen , Theodore Tso Cc: Joshua Brindle , Andrew Morton , casey@schaufler-ca.com, torvalds@linux-foundation.org, linux-security-module@vger.kernel.org, linux-kernel@vger.kernel.org, James Morris , Paul Moore In-Reply-To: <200709302205.58017.ak@suse.de> MIME-Version: 1.0 Content-Type: text/plain; charset=US-ASCII Content-Transfer-Encoding: 7BIT Message-ID: <760457.44360.qm@web36609.mail.mud.yahoo.com> Sender: linux-kernel-owner@vger.kernel.org X-Mailing-List: linux-kernel@vger.kernel.org Content-Length: 836 Lines: 25 --- Andi Kleen wrote: > Anyways; if someone wants to cripple their security for some > performance this way they can surely do this; but i don't think we should > offer it as a default configuration option (just as we don't have a > CONFIG_NULL_LSM even though there are undoubtedly systems that don't > care about permission checking[1]) > > -Andi > > [1] I bet I gave the linux-tiny crowd an idea now ;-) You would need authoritative LSM hooks for this. The current LSM additional restrictions model does not provide for this. Casey Schaufler casey@schaufler-ca.com - To unsubscribe from this list: send the line "unsubscribe linux-kernel" in the body of a message to majordomo@vger.kernel.org More majordomo info at http://vger.kernel.org/majordomo-info.html Please read the FAQ at http://www.tux.org/lkml/