Re: LSM Documentation and/or examples

From: Stephen Smalley (sds@private)
Date: Fri Oct 28 2005 - 05:52:07 PDT


On Thu, 2005-10-27 at 15:46 -0500, Mark Bainter wrote:
> I'm curious if there are some other examples out there that I can look
> at?  Preferably something simpler to get into than say SELinux.  Or is
> there some documentation I can read?  I looked over the documentation
> at immunix.org, but it is mostly an overview and then a list of
> functions.  Valuable and appreciated to be sure, but I was hoping for
> a bit more detail on the concepts and such.

I know that you said you wanted to look at something simpler than
SELinux, but did you look at the tech report on the implementation of
SELinux as a LSM?
http://www.nsa.gov/selinux/papers/module/t1.html

SELinux may be a little difficult to get into, but it should serve as a
good example for you; it has been subjected to a lot of scrutiny by
virtue of being in the mainline kernel, and it provides very extensive
coverage.

-- 
Stephen Smalley
National Security Agency



This archive was generated by hypermail 2.1.3 : Fri Oct 28 2005 - 05:56:08 PDT