Re: [RFC] cgroups: implement device whitelist lsm (v2)

Previous message: [thread] [date] [author]
Next message: [thread] [date] [author]
From: Serge E. Hallyn
Date: Thursday, March 13, 2008 - 7:38 am

Quoting James Morris (jmorris@namei.org):

True, but while this change simplifies the code a bit, the semantics
seem more muddled - devcg will be enforcing when CONFIG_CGROUP_DEV=y
and:

	SECURITY=n or
	rootplug is enabled
	capabilities is enabled
	smack is enabled
	selinux+capabilities is enabled

It will not be enforcing when
	dummy is loaded
	only selinux (and not capabilities) is loaded

If that's ok with people then I'm fine with it.  I suppose it should be
explained in the CONFIG_CGROUP_DEV help section, which it isn't in this
version I'm about to set.  Patch hitting the wire in a minute.

thanks,
-serge

--
Previous message: [thread] [date] [author]
Next message: [thread] [date] [author]

Messages in current thread:
[RFC] cgroups: implement device whitelist lsm (v2), Serge E. Hallyn, (Wed Mar 12, 8:27 pm)
Re: [RFC] cgroups: implement device whitelist lsm (v2), James Morris, (Thu Mar 13, 2:25 am)
Re: [RFC] cgroups: implement device whitelist lsm (v2), Serge E. Hallyn, (Thu Mar 13, 6:18 am)
Re: [RFC] cgroups: implement device whitelist lsm (v2), James Morris, (Thu Mar 13, 6:50 am)
Re: [RFC] cgroups: implement device whitelist lsm (v2), Serge E. Hallyn, (Thu Mar 13, 7:38 am)
Re: [RFC] cgroups: implement device whitelist lsm (v2), James Morris, (Thu Mar 13, 3:27 pm)
Re: [RFC] cgroups: implement device whitelist lsm (v2), Serge E. Hallyn, (Thu Mar 13, 3:46 pm)
Re: [RFC] cgroups: implement device whitelist lsm (v2), James Morris, (Thu Mar 13, 4:49 pm)
Re: [RFC] cgroups: implement device whitelist lsm (v2), Serge E. Hallyn, (Thu Mar 13, 6:41 pm)
Re: [RFC] cgroups: implement device whitelist lsm (v2), Casey Schaufler, (Thu Mar 13, 7:51 pm)
Re: [RFC] cgroups: implement device whitelist lsm (v2), Paul Menage, (Fri Mar 14, 2:16 am)
Re: [RFC] cgroups: implement device whitelist lsm (v2), Paul Menage, (Fri Mar 14, 2:18 am)
Re: [RFC] cgroups: implement device whitelist lsm (v2), Pavel Emelyanov, (Fri Mar 14, 2:28 am)
Re: [RFC] cgroups: implement device whitelist lsm (v2), Serge E. Hallyn, (Fri Mar 14, 6:54 am)
Re: [RFC] cgroups: implement device whitelist lsm (v2), Serge E. Hallyn, (Fri Mar 14, 6:58 am)
Re: [RFC] cgroups: implement device whitelist lsm (v2), Pavel Emelyanov, (Fri Mar 14, 6:58 am)
Re: [RFC] cgroups: implement device whitelist lsm (v2), Serge E. Hallyn, (Fri Mar 14, 7:00 am)
Re: [RFC] cgroups: implement device whitelist lsm (v2), Pavel Emelyanov, (Fri Mar 14, 7:05 am)
Re: [RFC] cgroups: implement device whitelist lsm (v2), Serge E. Hallyn, (Fri Mar 14, 7:05 am)
Re: [RFC] cgroups: implement device whitelist lsm (v2), Paul Menage, (Fri Mar 14, 7:12 am)
Re: [RFC] cgroups: implement device whitelist lsm (v2), Paul Menage, (Fri Mar 14, 7:15 am)
Re: [RFC] cgroups: implement device whitelist lsm (v2), Serge E. Hallyn, (Fri Mar 14, 7:35 am)
Re: [RFC] cgroups: implement device whitelist lsm (v2), Serge E. Hallyn, (Fri Mar 14, 7:37 am)
Re: [RFC] cgroups: implement device whitelist lsm (v2), Serge E. Hallyn, (Fri Mar 14, 7:42 am)
Re: [RFC] cgroups: implement device whitelist lsm (v2), Pavel Emelyanov, (Fri Mar 14, 8:07 am)
Re: [RFC] cgroups: implement device whitelist lsm (v2), Serge E. Hallyn, (Fri Mar 14, 8:45 am)
Re: [RFC] cgroups: implement device whitelist lsm (v2), Pavel Emelyanov, (Fri Mar 14, 8:54 am)
Re: [RFC] cgroups: implement device whitelist lsm (v2), Stephen Smalley, (Fri Mar 14, 9:57 am)
Re: [RFC] cgroups: implement device whitelist lsm (v2), Paul Menage, (Sat Mar 15, 5:57 pm)
Re: [RFC] cgroups: implement device whitelist lsm (v2), Paul Menage, (Sat Mar 15, 5:59 pm)