From: Chris Wright <chrisw@osdl.org>
To: Andrew Morton <akpm@osdl.org>
Cc: Chris Wright <chrisw@osdl.org>,
jmorris@redhat.com, serue@us.ibm.com,
linux-kernel@vger.kernel.org
Subject: Re: [patch 1/3] lsm: add bsdjail module
Date: Thu, 7 Oct 2004 11:52:40 -0700 [thread overview]
Message-ID: <20041007115240.C2357@build.pdx.osdl.net> (raw)
In-Reply-To: <20041007114039.6e861b2b.akpm@osdl.org>; from akpm@osdl.org on Thu, Oct 07, 2004 at 11:40:39AM -0700
* Andrew Morton (akpm@osdl.org) wrote:
> Chris Wright <chrisw@osdl.org> wrote:
> > * Andrew Morton (akpm@osdl.org) wrote:
> > Which feature are you concerned over, the additional hook or the
> > new module?
>
> I am concerned about the presence of new code - simple as that.
Understood.
> We need to be able to demonstrate that the new code is sufficiently useful
> to a sufficiently large number of people as to warrant the cost of
> maintaining it in the tree for the rest of eternity.
That's fine. Serge, can you enlighten us with an idea of the users of
this code?
> > The module is a no-op for anybody who doesn't want it.
>
> It still needs to be maintained.
Absolutely.
> > I can't vouch for the number of users of this module although I've seen
> > some positive feedback from users. One nice bit is that it goes a way
> > towards helping vserver which does have quite a few users.
>
> Tell us more.
One portion of the vserver project (that which has to do with security
and isolation) could be largely covered by this work. And vserver
is an active project with many users AFAICT. The vserver maintainer
has expressed some interest in this as well. The other portion of the
project, which does the resource limiting has a decent chance of working
well with something like CKRM or similar.
> > This module
> > really demonstrates one of the points of LSM...to support multiple
> > security models.
>
> Sure. But that doesn't mean that those modules have to live at kernel.org
> rather than, say, at bsdjail.sourceforge.net.
I agree, some userbase does wonders to justify mainlining the code.
thanks,
-chris
--
Linux Security Modules http://lsm.immunix.org http://lsm.bkbits.net
next prev parent reply other threads:[~2004-10-07 19:00 UTC|newest]
Thread overview: 38+ messages / expand[flat|nested] mbox.gz Atom feed top
2004-10-06 20:21 (patch 1/3) lsm: add control over /proc/<pid> visibility Serge Hallyn
2004-10-06 20:24 ` [patch 1/3] lsm: add bsdjail module Serge Hallyn
2004-10-06 23:26 ` Andrew Morton
2004-10-07 4:08 ` Serge E. Hallyn
2004-10-07 6:18 ` James Morris
2004-10-07 6:22 ` Andrew Morton
2004-10-07 16:06 ` Chris Wright
2004-10-07 18:40 ` Andrew Morton
2004-10-07 18:52 ` Chris Wright [this message]
2004-10-07 20:56 ` Serge E. Hallyn
2004-10-10 6:24 ` Herbert Poetzl
2004-10-07 12:06 ` Alan Cox
2004-10-07 19:01 ` [patch 2/3] " Serge E. Hallyn
2004-10-07 19:42 ` Chris Wright
2004-10-07 20:05 ` Andrew Morton
2004-10-08 18:05 ` Serge E. Hallyn
2004-10-10 10:41 ` Christoph Hellwig
2004-10-10 11:31 ` Serge E. Hallyn
2004-10-10 11:34 ` Christoph Hellwig
2004-10-11 13:47 ` Alan Cox
2004-10-12 7:00 ` Herbert Poetzl
2004-10-12 9:00 ` Christoph Hellwig
2004-10-12 12:27 ` Herbert Poetzl
2004-10-20 15:36 ` Christoph Hellwig
2004-10-20 19:18 ` Herbert Poetzl
2004-10-12 13:11 ` Serge E. Hallyn
2004-10-12 14:15 ` Christoph Hellwig
2004-10-12 22:35 ` Ulrich Drepper
2004-10-13 0:58 ` Serge E. Hallyn
2004-10-13 1:09 ` Ulrich Drepper
2004-10-13 1:22 ` Serge E. Hallyn
2004-10-13 15:26 ` Stephen Smalley
2004-10-13 1:11 ` Chris Wright
2004-10-13 14:25 ` Stephen Smalley
2004-10-06 20:25 ` [patch 3/3] lsm: add bsdjail documentation Serge Hallyn
2004-10-07 22:17 ` Matthias Urlichs
2004-10-08 20:02 ` Serge E. Hallyn
-- strict thread matches above, loose matches on Subject: below --
2004-11-22 1:51 [patch 1/3] lsm: add bsdjail module Colin Walters
Reply instructions:
You may reply publicly to this message via plain-text email
using any one of the following methods:
* Save the following mbox file, import it into your mail client,
and reply-to-all from there: mbox
Avoid top-posting and favor interleaved quoting:
https://en.wikipedia.org/wiki/Posting_style#Interleaved_style
* Reply using the --to, --cc, and --in-reply-to
switches of git-send-email(1):
git send-email \
--in-reply-to=20041007115240.C2357@build.pdx.osdl.net \
--to=chrisw@osdl.org \
--cc=akpm@osdl.org \
--cc=jmorris@redhat.com \
--cc=linux-kernel@vger.kernel.org \
--cc=serue@us.ibm.com \
/path/to/YOUR_REPLY
https://kernel.org/pub/software/scm/git/docs/git-send-email.html
* If your mail client supports setting the In-Reply-To header
via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line
before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox