public inbox for linux-kernel@vger.kernel.org
 help / color / mirror / Atom feed
From: Pavel Machek <pavel@ucw.cz>
To: David Wagner <daw-usenet@taverner.cs.berkeley.edu>
Cc: linux-kernel@vger.kernel.org
Subject: Re: AppArmor FAQ
Date: Sat, 9 Jun 2007 21:38:53 +0200	[thread overview]
Message-ID: <20070609193853.GA6663@elf.ucw.cz> (raw)
In-Reply-To: <f03ujo$cta$1@taverner.cs.berkeley.edu>

Hi!

> >> Maybe you'd like to confine the PHP interpreter to limit what it can do.
> >> That might be a good application for something like AppArmor.  You don't
> >> need comprehensive information flow control for that kind of use, and
> >> it would likely just get in the way.
> >
> >SELinux can do this, it's policy-flexible.  You can even simulate a 
> >pathame-based policy language with a consequential loss of control:
> 
> I have no doubt that SELinux can do that, but that has about as much
> relevance to my point as the price of tea in China does.  I can use a
> screwdriver to drive in a nail into my wall, too, if I really wanted to,
> but that doesn't mean toolmakers should stop manufacturing hammers.

Well, we are talking about kernel here, and if screwdrivers work well
enough to drive nails into walls, we'll not allow hammers in.

> My point is that there are some tasks where it's plausible that AppArmor
> might well be a better (easier-to-use) tool for the job.  I'm

If SELinux can do the task, AA people are welcome to port their
userland apps to SELinux to make it user friendly. We do _not_ provide
user friendly services in kernel.

Someone wanted shell inside kernel because it is convenient to
him. Too bad, not going to be merged.
								Pavel
-- 
(english) http://www.livejournal.com/~pavelmachek
(cesky, pictures) http://atrey.karlin.mff.cuni.cz/~pavel/picture/horses/blog.html

  reply	other threads:[~2007-06-09 19:39 UTC|newest]

Thread overview: 68+ messages / expand[flat|nested]  mbox.gz  Atom feed  top
2007-04-16 21:33 AppArmor FAQ John Johansen
2007-04-17  0:20 ` James Morris
2007-04-17 15:03   ` David Safford
2007-04-17 16:00     ` Karl MacMillan
2007-04-17 18:05       ` Andi Kleen
2007-04-17 17:47         ` James Morris
2007-04-17 18:10           ` Andi Kleen
2007-04-17 20:19             ` Casey Schaufler
2007-04-17 20:50               ` James Morris
2007-04-17 21:16               ` Andi Kleen
2007-04-17 21:41                 ` Karl MacMillan
2007-04-17 21:51                   ` David Wagner
2007-04-17 22:17                     ` Alan Cox
2007-04-18  1:34                     ` James Morris
2007-04-18  1:55                       ` David Wagner
2007-04-18  2:20                         ` James Morris
2007-04-18  2:31                           ` David Wagner
2007-04-17 22:12                   ` Andi Kleen
2007-04-17 22:29                     ` Karl MacMillan
2007-04-17 21:58                 ` Alan Cox
2007-04-18 13:45                   ` James Morris
2007-04-18 14:33                     ` Shaya Potter
2007-04-18 19:41                     ` Crispin Cowan
2007-04-18 20:03                       ` Shaya Potter
2007-04-18 21:14                       ` James Morris
2007-04-19 16:35                         ` David Wagner
2007-04-19 17:39                           ` Stephen Smalley
2007-04-19 20:47                             ` David Wagner
2007-04-24  0:58                               ` Crispin Cowan
2007-04-24  2:03                                 ` Joshua Brindle
2007-04-25  1:03                                 ` Joshua Brindle
2007-04-19 17:14                       ` Stephen Smalley
2007-04-19 20:08                         ` David Wagner
2007-04-19 21:03                           ` Stephen Smalley
2007-04-19 21:08                             ` James Morris
2007-06-09 21:01                       ` Pavel Machek
2007-06-09 21:28                         ` david
2007-06-09 23:02                           ` Pavel Machek
2007-06-10  0:06                             ` david
2007-04-18 20:15                     ` David Lang
2007-04-19 17:27                       ` Stephen Smalley
2007-04-19 18:19                     ` Bernd Eckenfels
2007-04-19 20:19                       ` James Morris
2007-04-17 21:48               ` Karl MacMillan
2007-04-17 23:12                 ` Casey Schaufler
2007-04-17 22:26             ` Karl MacMillan
2007-04-19 17:46         ` Stephen Smalley
2007-04-20 18:45           ` David Lang
2007-04-20 19:23             ` Karl MacMillan
2007-04-17 23:09     ` Crispin Cowan
2007-04-17 23:20       ` Karl MacMillan
2007-04-17 23:53         ` David Wagner
2007-04-18  1:56           ` James Morris
2007-04-18  2:08             ` David Wagner
2007-06-09 19:38               ` Pavel Machek [this message]
2007-04-19 17:56       ` Stephen Smalley
2007-04-19 20:54         ` David Wagner
2007-04-19 21:17           ` Stephen Smalley
2007-04-17 21:55   ` Karl MacMillan
2007-04-17 22:55     ` Crispin Cowan
2007-04-17 23:13       ` Karl MacMillan
2007-06-09 14:11       ` Pavel Machek
2007-04-18  7:21     ` Rob Meijer
2007-04-18  7:08       ` David Lang
2007-04-18 13:33         ` James Morris
2007-04-18 12:15       ` Joshua Brindle
2007-04-18 13:31         ` Casey Schaufler
2007-04-18 14:05         ` Rob Meijer

Reply instructions:

You may reply publicly to this message via plain-text email
using any one of the following methods:

* Save the following mbox file, import it into your mail client,
  and reply-to-all from there: mbox

  Avoid top-posting and favor interleaved quoting:
  https://en.wikipedia.org/wiki/Posting_style#Interleaved_style

* Reply using the --to, --cc, and --in-reply-to
  switches of git-send-email(1):

  git send-email \
    --in-reply-to=20070609193853.GA6663@elf.ucw.cz \
    --to=pavel@ucw.cz \
    --cc=daw-usenet@taverner.cs.berkeley.edu \
    --cc=linux-kernel@vger.kernel.org \
    /path/to/YOUR_REPLY

  https://kernel.org/pub/software/scm/git/docs/git-send-email.html

* If your mail client supports setting the In-Reply-To header
  via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox