Re: Possible system call interface for LSM

From: Greg KH (gregat_private)
Date: Sun Aug 12 2001 - 17:48:53 PDT

  • Next message: jmjonesat_private: "Re: Possible system call interface for LSM"

    On Sun, Aug 12, 2001 at 08:07:34PM -0400, jmjonesat_private wrote:
    > On Sat, 11 Aug 2001, Greg KH wrote:
    > 
    > > 
    > > Actually, if the SELinux kernel module allows that to happen by _any_
    > > random user app, then the kernel module has a bug :)
    > > 
    > 
    > >From out-of-band...
    > 
    > Can't a security module block it's own removal using the delete_module 
    > hook?  If not, wouldn't it solve this problem completely to make sure a
    > security module CAN NOT be removed without the module's permission?
    
    The hook is already there to let you determine if you want to be
    unloaded or not.  So yes, I agree with you, eek, what's happening :)
    
    greg k-h
    
    _______________________________________________
    linux-security-module mailing list
    linux-security-moduleat_private
    http://mail.wirex.com/mailman/listinfo/linux-security-module
    



    This archive was generated by hypermail 2b30 : Sun Aug 12 2001 - 17:51:29 PDT