All of lore.kernel.org
 help / color / mirror / Atom feed
From: Pavel Machek <pavel@ucw.cz>
To: James Morris <jmorris@namei.org>
Cc: John Johansen <john.johansen@canonical.com>,
	linux-kernel@vger.kernel.org,
	linux-security-module@vger.kernel.org
Subject: Re: [AppArmor #7 0/13] AppArmor security module
Date: Thu, 26 Aug 2010 09:01:45 +0200	[thread overview]
Message-ID: <20100826070145.GA11959@elf.ucw.cz> (raw)
In-Reply-To: <alpine.LRH.2.00.1008052023030.14772@tundra.namei.org>

On Thu 2010-08-05 20:27:24, James Morris wrote:
> On Thu, 5 Aug 2010, Pavel Machek wrote:
> 
> > > Note that I added the patch below to update AA against the latest 
> > > version of path_truncate:
> > 
> > Ok, so now we have two name-based "security" modules. Can we at least
> > drop TOMOYO? That seems to have all apparmor disadvantages plus some
> > more...
> 
> No.  The policy is that any security module which implements an access 
> control scheme and meets a well-defined security goal, and passes 
> technical review, may be merged.
> 
> aka, The Arjan Protocol:
> 
> http://kerneltrap.org/Linux/Documenting_Security_Module_Intent

It seems that security subsystem has lower standards than rest of the
kernel. Sad.
									Pavel

-- 
(english) http://www.livejournal.com/~pavelmachek
(cesky, pictures) http://atrey.karlin.mff.cuni.cz/~pavel/picture/horses/blog.html

      reply	other threads:[~2010-08-26  7:02 UTC|newest]

Thread overview: 30+ messages / expand[flat|nested]  mbox.gz  Atom feed  top
2010-07-29 21:47 [AppArmor #7 0/13] AppArmor security module John Johansen
2010-07-29 21:47 ` [PATCH 01/13] AppArmor: misc. base functions and defines John Johansen
2010-07-30  9:20   ` Pekka Enberg
2010-07-30 10:01     ` John Johansen
2010-07-30 10:53       ` Pekka Enberg
2010-07-30 14:24         ` Changli Gao
2010-07-30 15:01           ` Pekka Enberg
2010-07-29 21:47 ` [PATCH 02/13] AppArmor: basic auditing infrastructure John Johansen
2010-07-29 21:47 ` [PATCH 03/13] AppArmor: contexts used in attaching policy to system objects John Johansen
2010-07-29 21:48 ` [PATCH 04/13] AppArmor: core policy routines John Johansen
2010-07-29 21:48 ` [PATCH 05/13] AppArmor: dfa match engine John Johansen
2010-07-29 21:48 ` [PATCH 06/13] AppArmor: policy routines for loading and unpacking policy John Johansen
2010-07-29 21:48 ` [PATCH 07/13] AppArmor: userspace interfaces John Johansen
2010-07-29 21:48 ` [PATCH 08/13] AppArmor: file enforcement routines John Johansen
2010-07-29 21:48 ` [PATCH 09/13] AppArmor: mediation of non file objects John Johansen
2010-07-29 21:48 ` [PATCH 10/13] AppArmor: functions for domain transitions John Johansen
2010-07-29 21:48 ` [PATCH 11/13] AppArmor: LSM interface, and security module initialization John Johansen
2010-07-29 21:48 ` [PATCH 12/13] AppArmor: Enable configuring and building of the AppArmor security module John Johansen
2010-07-29 21:48 ` [PATCH 13/13] AppArmor: update Maintainer and Documentation John Johansen
2010-07-29 23:05 ` [AppArmor #7 0/13] AppArmor security module James Morris
2010-07-30  1:45   ` Tetsuo Handa
2010-07-30  2:04     ` John Johansen
2010-07-30  2:26       ` Tetsuo Handa
2010-07-30  3:50         ` James Morris
2010-07-30  5:39           ` Tetsuo Handa
2010-07-30  4:48   ` Casey Schaufler
2010-08-05  6:24   ` Pavel Machek
2010-08-05  9:58     ` Jan III Sobieski
2010-08-05 10:27     ` James Morris
2010-08-26  7:01       ` Pavel Machek [this message]

Reply instructions:

You may reply publicly to this message via plain-text email
using any one of the following methods:

* Save the following mbox file, import it into your mail client,
  and reply-to-all from there: mbox

  Avoid top-posting and favor interleaved quoting:
  https://en.wikipedia.org/wiki/Posting_style#Interleaved_style

* Reply using the --to, --cc, and --in-reply-to
  switches of git-send-email(1):

  git send-email \
    --in-reply-to=20100826070145.GA11959@elf.ucw.cz \
    --to=pavel@ucw.cz \
    --cc=jmorris@namei.org \
    --cc=john.johansen@canonical.com \
    --cc=linux-kernel@vger.kernel.org \
    --cc=linux-security-module@vger.kernel.org \
    /path/to/YOUR_REPLY

  https://kernel.org/pub/software/scm/git/docs/git-send-email.html

* If your mail client supports setting the In-Reply-To header
  via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line before the message body.
This is an external index of several public inboxes,
see mirroring instructions on how to clone and mirror
all data and code used by this external index.