Re: [RFC][PATCH] Pass requested protection to security_file_mmap/mprotect hooks

From: Stephen Smalley (sds@private)
Date: Wed Feb 23 2005 - 05:02:05 PST


On Tue, 2005-02-22 at 13:01 -0800, Chris Wright wrote:
> By heuristics did you mean taking current->personality into account and
> trying to guess what the caller asked for?

Yes.  Even if current->personality has READ_IMPLIES_EXEC set, some of
the application (and ld.so) requests will explicitly include PROT_EXEC,
and we don't really want to suppress checking of those execute requests
as well.

-- 
Stephen Smalley <sds@private>
National Security Agency



This archive was generated by hypermail 2.1.3 : Wed Feb 23 2005 - 07:51:21 PST