From mboxrd@z Thu Jan 1 00:00:00 1970 Return-Path: Received: (majordomo@vger.kernel.org) by vger.kernel.org via listexpand id S1757535AbYCMW2M (ORCPT ); Thu, 13 Mar 2008 18:28:12 -0400 Received: (majordomo@vger.kernel.org) by vger.kernel.org id S1753415AbYCMW15 (ORCPT ); Thu, 13 Mar 2008 18:27:57 -0400 Received: from namei.org ([69.55.235.186]:52925 "EHLO us.intercode.com.au" rhost-flags-OK-OK-OK-FAIL) by vger.kernel.org with ESMTP id S1752341AbYCMW14 (ORCPT ); Thu, 13 Mar 2008 18:27:56 -0400 Date: Fri, 14 Mar 2008 09:27:32 +1100 (EST) From: James Morris X-X-Sender: jmorris@us.intercode.com.au To: "Serge E. Hallyn" cc: lkml , linux-security-module@vger.kernel.org, Greg KH , Stephen Smalley , Casey Schaufler , Pavel Emelianov Subject: Re: [RFC] cgroups: implement device whitelist lsm (v2) In-Reply-To: <20080313143803.GA11265@sergelap.austin.ibm.com> Message-ID: References: <20080313032749.GA13258@sergelap.austin.ibm.com> <20080313131818.GA9771@sergelap.austin.ibm.com> <20080313143803.GA11265@sergelap.austin.ibm.com> MIME-Version: 1.0 Content-Type: TEXT/PLAIN; charset=US-ASCII Sender: linux-kernel-owner@vger.kernel.org List-ID: X-Mailing-List: linux-kernel@vger.kernel.org On Thu, 13 Mar 2008, Serge E. Hallyn wrote: > True, but while this change simplifies the code a bit, the semantics > seem more muddled - devcg will be enforcing when CONFIG_CGROUP_DEV=y > and: > > SECURITY=n or > rootplug is enabled > capabilities is enabled > smack is enabled > selinux+capabilities is enabled Well, this is how real systems are going to be deployed. It becomes confusing, IMHO, if you have to change which secondary LSM you stack with SELinux to enable a cgroup feature. -- James Morris