Return-Path: Received: (majordomo@vger.kernel.org) by vger.kernel.org via listexpand id S1760737Ab0FQUva (ORCPT ); Thu, 17 Jun 2010 16:51:30 -0400 Received: from earthlight.etchedpixels.co.uk ([81.2.110.250]:55548 "EHLO www.etchedpixels.co.uk" rhost-flags-OK-OK-OK-FAIL) by vger.kernel.org with ESMTP id S1756841Ab0FQUv1 (ORCPT ); Thu, 17 Jun 2010 16:51:27 -0400 Date: Thu, 17 Jun 2010 21:53:49 +0100 From: Alan Cox To: Kees Cook Cc: James Morris , linux-kernel@vger.kernel.org, Randy Dunlap , Andrew Morton , Jiri Kosina , Dave Young , Martin Schwidefsky , Roland McGrath , Oleg Nesterov , "H. Peter Anvin" , David Howells , Ingo Molnar , Peter Zijlstra , "Eric W. Biederman" , linux-doc@vger.kernel.org, Stephen Smalley , Daniel J Walsh , linux-security-module@vger.kernel.org Subject: Re: [PATCH] ptrace: allow restriction of ptrace scope Message-ID: <20100617215349.2fac02f5@lxorguk.ukuu.org.uk> In-Reply-To: <20100617170453.GV24749@outflux.net> References: <20100616221833.GM24749@outflux.net> <20100617000120.13071be8@lxorguk.ukuu.org.uk> <20100616232230.GP24749@outflux.net> <20100617170453.GV24749@outflux.net> X-Mailer: Claws Mail 3.7.6 (GTK+ 2.18.9; x86_64-redhat-linux-gnu) Mime-Version: 1.0 Content-Type: text/plain; charset=US-ASCII Content-Transfer-Encoding: 7bit Sender: linux-kernel-owner@vger.kernel.org List-ID: X-Mailing-List: linux-kernel@vger.kernel.org Content-Length: 662 Lines: 15 > > SELinux users would not need the other LSM, and stacking is thus not > > required. > > But if a user wants to disable ptrace using the SELinux LSM and then > also disable sticky-symlinks via the ItsHideous LSM, they're out of luck. Thats a nonsensical configuration so we don't care. If you are using SELinux you just do it via SELinux. If you are doing it via UbuntuHasToBeDifferent then you do it via that. -- To unsubscribe from this list: send the line "unsubscribe linux-kernel" in the body of a message to majordomo@vger.kernel.org More majordomo info at http://vger.kernel.org/majordomo-info.html Please read the FAQ at http://www.tux.org/lkml/