Re: Possible system call interface for LSM

From: richard offer (offerat_private)
Date: Thu Aug 09 2001 - 15:55:10 PDT

  • Next message: David Wagner: "Re: Possible system call interface for LSM"

    * frm dawat_private "08/09/01 17:49:58 +0000" | sed '1,$s/^/*
    /'
    *
    * Crispin Cowan  wrote:
    *> Asking Linus for a single system call, and then multiplexing it to serve
    *> whatever LSM modules need, was actually a decision we came to some months
    *> ago.
    * 
    * Did we?  I thought we had a discussion about syscalls vs /proc
    * interface, and I came away with the tentative impression that
    * /proc might work well enough for many (most?) of the modules.
    
    I really don't like the idea of forcing the use of the /proc filesystem
    just to enable the use of LSM.
    
    This could affect the uptake of LSM in the embedded space.
    
    And using /proc is going to be slower than a system call, which maybe okay
    for Janus, could for other policies, SELinux ?
    
    
    richard.
    
    -----------------------------------------------------------------------
    Richard Offer                     Technical Lead, Trust Technology, SGI
    "Specialization is for insects"
    _______________________________________________________________________
    
    
    _______________________________________________
    linux-security-module mailing list
    linux-security-moduleat_private
    http://mail.wirex.com/mailman/listinfo/linux-security-module
    



    This archive was generated by hypermail 2b30 : Thu Aug 09 2001 - 15:56:33 PDT