RE: File descriptors: LSM should support them in phase 1.

From: Matt Block (mattat_private)
Date: Sat Aug 04 2001 - 10:03:48 PDT

  • Next message: jmjonesat_private: "Re: NFSv4"

    http://www.getrewted.net is the project site for GR Security.  Should
    have included that.
    
    -----Original Message-----
    From: linux-security-module-adminat_private
    [mailto:linux-security-module-adminat_private] On Behalf Of richard
    offer
    Sent: Friday, August 03, 2001 8:33 PM
    To: linux-security-moduleat_private
    Subject: Re: File descriptors: LSM should support them in phase 1.
    
    I'm out of time and am giving up (for the time being)
    
        1) The solar designer port is for 2.2
    
        2) It works by intercepting the fds at exec time, so passing fd to
    (for
    example) the read hook isn't going to help using their existing
    implementation.
    
        3) Adding a open()/close() (or possibly post_*) hook to check for
    the special fds is right out as that isn't going to get past Greg :-)
    
    If anyone has any suggested alternative implementations I'll try to fit
    in some more work on it.
    -----------------------------------------------------------------------
    Richard Offer                     Technical Lead, Trust Technology, SGI
    "Specialization is for insects"
    _______________________________________________________________________
    
    
    _______________________________________________
    linux-security-module mailing list
    linux-security-moduleat_private
    http://mail.wirex.com/mailman/listinfo/linux-security-module
    



    This archive was generated by hypermail 2b30 : Sat Aug 04 2001 - 10:04:31 PDT