linux-security-module.vger.kernel.org archive mirror
 help / color / mirror / Atom feed
From: "Dr. Greg" <greg@enjellic.com>
To: Linus Torvalds <torvalds@linux-foundation.org>
Cc: linux-security-module@vger.kernel.org, corbet@lwn.net
Subject: Re: A formal request for process clarifications.
Date: Mon, 15 Dec 2025 10:57:17 -0600	[thread overview]
Message-ID: <20251215165717.GA12485@wind.enjellic.com> (raw)
In-Reply-To: <CAHk-=whqzs-3u6Y7UC03A_XJEy6H1kNWvFO_A8jqsuob7SZCLA@mail.gmail.com>

On Mon, Dec 15, 2025 at 07:38:58PM +1200, Linus Torvalds wrote:

Good morning Linus, thanks for taking the time to respond.

> On Mon, 15 Dec 2025 at 19:13, Dr. Greg <greg@enjellic.com> wrote:
> >
> > Three years ago our team had submitted for review our TSEM LSM that
> > provides a framework for generic security modeling,

> If you can't convince the LSM people to take your code, you sure can't
> convince me.
> 
> I already think we have too many of those pointless things. There's a
> fine line between diversity and "too much confusion because everybody
> thinks they know best". And the linux security modules passed that
> line years ago.
> 
> So my suggestion is to standardize on normal existing security models
> instead of thinking that you can do better by making yet another one.
> Or at least work with the existing people instead of trying to bypass
> them and ignoring what they tell you.
> 
> Yes, I know that security people always think they know best, and they
> all disagree with each other, which is why we already have tons of
> security modules.  Ask ten people what model is the right one, and you
> get fifteen different answers.
> 
> I'm not in the least interested in becoming some kind of arbiter or
> voice of sanity in this.

First, to be very clear, we are not asking for any kind of
intervention or arbitration on your part.

Second and most importantly.  You've been belly-aching about this
problem for as long as I can remember and you I go back to 1992
together with Linux.

You, and only you, can fix the problem if you want it fixed.  Issue an
immediate statement that you will no longer accept any code that
implements an 'LSM'.

That will drive security development out of the kernel, which is where
it is going to go eventually anyway OR it will drive the security
community to try and fix what it considers to be the challenges with
eBPF when it comes to building security solutions.

Somewhat paradoxically in all of this, TSEM isn't even an LSM that
implements security policy.  It is generic infrastructure that was
built to address the very problem you are bitching about.

If Linux is really about technology, as you have continually
advocated, then there has to be an open playing field for
contributors.  Absent that, Linux will balkanize, the same way the
commercial Unix implementations did, around corporate driven
interests and motivations.

We will pursue the open playing field issue through the TAB if
necessary.


>               Linus

Once again, with all due respect, fix the problem if it annoys you,
you would be doing a lot of people a favor.

Best wishes for a pleasant holiday season to you and your family.

As always,
Dr. Greg

The Quixote Project - Flailing at the Travails of Cybersecurity
              https://github.com/Quixote-Project

      reply	other threads:[~2025-12-15 17:20 UTC|newest]

Thread overview: 3+ messages / expand[flat|nested]  mbox.gz  Atom feed  top
2025-12-15  7:08 A formal request for process clarifications Dr. Greg
2025-12-15  7:38 ` Linus Torvalds
2025-12-15 16:57   ` Dr. Greg [this message]

Reply instructions:

You may reply publicly to this message via plain-text email
using any one of the following methods:

* Save the following mbox file, import it into your mail client,
  and reply-to-all from there: mbox

  Avoid top-posting and favor interleaved quoting:
  https://en.wikipedia.org/wiki/Posting_style#Interleaved_style

* Reply using the --to, --cc, and --in-reply-to
  switches of git-send-email(1):

  git send-email \
    --in-reply-to=20251215165717.GA12485@wind.enjellic.com \
    --to=greg@enjellic.com \
    --cc=corbet@lwn.net \
    --cc=linux-security-module@vger.kernel.org \
    --cc=torvalds@linux-foundation.org \
    /path/to/YOUR_REPLY

  https://kernel.org/pub/software/scm/git/docs/git-send-email.html

* If your mail client supports setting the In-Reply-To header
  via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox;
as well as URLs for NNTP newsgroup(s).