Return-Path: Received: (majordomo@vger.kernel.org) by vger.kernel.org via listexpand id S1758149AbZC0NEp (ORCPT ); Fri, 27 Mar 2009 09:04:45 -0400 Received: (majordomo@vger.kernel.org) by vger.kernel.org id S1752401AbZC0NEh (ORCPT ); Fri, 27 Mar 2009 09:04:37 -0400 Received: from mail-in-03.arcor-online.net ([151.189.21.43]:53254 "EHLO mail-in-03.arcor-online.net" rhost-flags-OK-OK-OK-OK) by vger.kernel.org with ESMTP id S1751325AbZC0NEg (ORCPT ); Fri, 27 Mar 2009 09:04:36 -0400 X-DKIM: Sendmail DKIM Filter v2.8.2 mail-in-07.arcor-online.net E16893CA6DB Date: Fri, 27 Mar 2009 14:04:32 +0100 (CET) From: Bodo Eggert <7eggert@gmx.de> To: Pavel Machek cc: Bodo Eggert <7eggert@gmx.de>, James Morris , kernel list Subject: Re: TOMOYO in linux-next In-Reply-To: <20090327114224.GF2585@elf.ucw.cz> Message-ID: References: <20090327114224.GF2585@elf.ucw.cz> MIME-Version: 1.0 Content-Type: TEXT/PLAIN; charset=us-ascii Sender: linux-kernel-owner@vger.kernel.org List-ID: X-Mailing-List: linux-kernel@vger.kernel.org Content-Length: 1182 Lines: 28 On Fri, 27 Mar 2009, Pavel Machek wrote: > On Fri 2009-03-27 10:28:07, Bodo Eggert wrote: > > Pavel Machek wrote: > > > I don't think merging that is good idea. Security should be doable > > > without making shell-like glob matching... > > > > How do you suppose a security system should handle mozilla modifying > > ~/.bashrc differently from downloading something to ~/pr0n.jpg? > > How does shell-like glob matching help there? You'd need to parse > /etc/passwd to find all ~ directories... That is, if you'd use HOME=`dd if=/dev/urandom ...`. If you have your users in /home/user, you can tell /home/*/.* is bad, /home/*/[^.]* is OK. How would you exclude mozilla from writing to .* then? ".a" is bad, ".b" is bad ...? or "A" is OK, "a" is OK, "zzzzzzzzzzzzz" is OK"? Either way, you'd need several universes to store the security profile. -- The enemy diversion you have been ignoring will be the main attack. -- To unsubscribe from this list: send the line "unsubscribe linux-kernel" in the body of a message to majordomo@vger.kernel.org More majordomo info at http://vger.kernel.org/majordomo-info.html Please read the FAQ at http://www.tux.org/lkml/