From mboxrd@z Thu Jan 1 00:00:00 1970 From: Christian Stroetmann Subject: Re: [PATCH] security: Yama LSM Date: Wed, 23 Jun 2010 08:03:08 +0200 Message-ID: <4C21A39C.6040406@ontolinux.com> References: <20100621213424.GG24749@outflux.net> <201006220028.o5M0Sbx7062650@www262.sakura.ne.jp> <20100622011452.GN24749@outflux.net> <4C20ABC0.5050908@nokia.com> <20100622160613.GC5876@outflux.net> Mime-Version: 1.0 Content-Type: text/plain; charset=ISO-8859-1; format=flowed Content-Transfer-Encoding: 7bit Cc: Linux Kernel Mailing List , Linux File System ML , Linux Security Module ML To: ext Kees Cook Return-path: In-Reply-To: <20100622160613.GC5876@outflux.net> Sender: linux-security-module-owner@vger.kernel.org List-Id: linux-fsdevel.vger.kernel.org On 22.06.2010 18:06, ext Kees Cook wrote: > Hi Dmitry, > > On Tue, Jun 22, 2010 at 03:25:36PM +0300, Dmitry Kasatkin wrote: > >> What is YAMA? >> > "Yama" is just the name of the LSM. It's inspired by: > http://en.wikipedia.org/wiki/Yama > Really? > >> Where is the tree? >> > At the moment: > http://kernel.ubuntu.com/git?p=kees/linux-2.6.git;a=shortlog;h=refs/heads/yama > > -Kees > "You've already had those suggestions some days ago. Use a security module, either by using something like SELinux (where you can do this just fine as far as I can see including exceptions by label for problem apps)", [Alan Cox, 2010-06-08], or integrate it into an already existing solution eg. grsecurity (www.grsecurity.net). Christian Stroetmann