linux-kernel.vger.kernel.org archive mirror
 help / color / mirror / Atom feed
* [PATCH v9 0/2] security: Yama LSM
@ 2011-12-19 22:17 Kees Cook
  2011-12-19 22:17 ` [PATCH 1/2] security: create task_free security callback Kees Cook
  2011-12-19 22:17 ` [PATCH 2/2] security: Yama LSM Kees Cook
  0 siblings, 2 replies; 5+ messages in thread
From: Kees Cook @ 2011-12-19 22:17 UTC (permalink / raw)
  To: linux-kernel
  Cc: linux-security-module, Roland McGrath, James Morris,
	kernel-hardening

As discussed at the Linux Security Summit, I'm resubmitting this
code. As an LSM, it has coherent policy around expanding specific DAC
behaviors. There is no need for it to be a full-blown MAC, since it is
not intended to be one, but rather to be a simplified expansion to DAC,
with system-wide knobs. See the specific patches for details...

This version only contains the ptrace restrictions, since a path has
been cleared for that (thanks Roland). The link restriction discussion
can continue separately. In the meantime, I will carry it as a patch here:
http://git.kernel.org/?p=linux/kernel/git/kees/linux.git;a=shortlog;h=refs/heads/yama

Thanks,

-Kees


^ permalink raw reply	[flat|nested] 5+ messages in thread

end of thread, other threads:[~2011-12-21 20:18 UTC | newest]

Thread overview: 5+ messages (download: mbox.gz follow: Atom feed
-- links below jump to the message on this page --
2011-12-19 22:17 [PATCH v9 0/2] security: Yama LSM Kees Cook
2011-12-19 22:17 ` [PATCH 1/2] security: create task_free security callback Kees Cook
2011-12-19 22:17 ` [PATCH 2/2] security: Yama LSM Kees Cook
2011-12-21  5:25   ` [kernel-hardening] " John Johansen
2011-12-21 20:18     ` Kees Cook

This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox;
as well as URLs for NNTP newsgroup(s).