linux-security-module.vger.kernel.org archive mirror
 help / color / mirror / Atom feed
* Re: LSM that blocks execution of the code from the anonymous pages
       [not found]   ` <88b9444e-08bc-4240-7943-298070dfc47c@omprussia.ru>
@ 2020-09-17 20:53     ` Mimi Zohar
  0 siblings, 0 replies; only message in thread
From: Mimi Zohar @ 2020-09-17 20:53 UTC (permalink / raw)
  To: Igor Zhbanov, linux-integrity; +Cc: linux-security-module

Hi Igor,

(Reminder the Linux kernel mailing lists convention is to inline/bottom
post.)

On Thu, 2020-09-17 at 23:39 +0300, Igor Zhbanov wrote:
> My question is more about whether this functionality fits into IMA's
> responsibility. I.e. I can propose the changes as the extension of IMA's
> functionality (which I think it would be better), or I could create a separate
> LSM if this functionality doesn't align with IMA's purpose for some reason.
> This is the first question.
> 
> And the second question, what kind of operation modes do you think would
> be useful?
> 
> 1) no anonymous code for privileged processes (as currently),
> 2) no anonymous code for all processes,
> 3) no anonymous code for all processes with xattr-based exceptions (may be
>       with xattr value signing)

These are generic questions not dependent on whether this would be
upstreamed as an independent LSM or as part of IMA.  For this reason,
I've Cc'ed the LSM mailing list.

Mimi

> 
> For #3 I definitely would prefer to implement the code as a part of IMA
> because of sharing of xattrs cache, etc. to avoid reinventing the wheel.


^ permalink raw reply	[flat|nested] only message in thread

only message in thread, other threads:[~2020-09-17 21:22 UTC | newest]

Thread overview: (only message) (download: mbox.gz follow: Atom feed
-- links below jump to the message on this page --
     [not found] <5f166ecd-38e4-a808-c377-683aabf6bf65@omprussia.ru>
     [not found] ` <2ba01c4961b2b967bb314e2d618a92e91d4fe511.camel@linux.ibm.com>
     [not found]   ` <88b9444e-08bc-4240-7943-298070dfc47c@omprussia.ru>
2020-09-17 20:53     ` LSM that blocks execution of the code from the anonymous pages Mimi Zohar

This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox;
as well as URLs for NNTP newsgroup(s).