public inbox for linux-kernel@vger.kernel.org
 help / color / mirror / Atom feed
From: Crispin Cowan <crispin@crispincowan.com>
To: Peter Dolding <oiaohm@gmail.com>
Cc: linux-kernel@vger.kernel.org, linux-security-module@vger.kernel.org
Subject: Re: Linux Security *Module* Framework (Was: LSM conversion to static interface)
Date: Tue, 30 Oct 2007 23:43:06 -0700	[thread overview]
Message-ID: <472823FA.80303@crispincowan.com> (raw)
In-Reply-To: <e7d8f83e0710301921m3460f8dfkce72c4fc549ded4a@mail.gmail.com>

Peter Dolding wrote:
> Lets end the bitrot.  Start having bits go into the main OS security
> features where they should be.
>   
Linus categorically rejected this idea, several times, very clearly.

He did so because the security community cannot agree on a
one-true-standard for what that OS security feature set should be. From
looking at this thread and many others, he is correct; there is no
consensus on what the feature set should be.

So you can wish for the "main OS security features" all you want, but it
is not going to happen without a miraculous degree of consensus abruptly
arising.

On the contrary, security, done well, is a tight fitting suit. It must
be tight, or it allows too much slack and attackers can exploit that. To
make it tight, it must be tailored to the situation at hand. That means
that there may *never* be a consensus on the "one true way", because it
could be that there is no "one true way". It could be that SMACK is best
in some cases, AppArmor in others, SELinux in others yet again, MLS in
others, etc. etc.

I agree with Casey; LSM may not be perfect, but it is a great deal more
consensus than I have seen anywhere else in the security community. Your
desire that AppArmor and SELinux should share code has already happened:
LSM *is* the sharable code base between AppArmor, SELinux, and SMACK and
TOMOYO, and MultiADM, etc.

It certainly can be improved, but it is not in need of wholesale
replacement, and especially not without a clear design that addresses
clearly stated problems that lots of people are having.

Crispin

-- 
Crispin Cowan, Ph.D.               http://crispincowan.com/~crispin
CEO, Mercenary Linux		   http://mercenarylinux.com/
	       Itanium. Vista. GPLv3. Complexity at work


  parent reply	other threads:[~2007-10-31  6:42 UTC|newest]

Thread overview: 103+ messages / expand[flat|nested]  mbox.gz  Atom feed  top
2007-10-29 19:04 Linux Security *Module* Framework (Was: LSM conversion to static interface) Rob Meijer
2007-10-29 19:41 ` Crispin Cowan
2007-10-30  5:13   ` Peter Dolding
2007-10-30  7:14     ` Defense in depth: LSM *modules*, not a static interface Cliffe
2007-10-30  6:55       ` Al Viro
2007-10-30  7:55         ` Crispin Cowan
2007-10-30 15:01           ` Casey Schaufler
2007-10-30  8:00         ` Cliffe
2007-10-30 12:30       ` Simon Arlott
2007-11-06  3:46         ` Crispin Cowan
2007-11-06  7:26           ` Cliffe
2007-11-06 23:59             ` Peter Dolding
2007-11-07  3:50               ` Cliffe
2007-11-07  3:35                 ` Casey Schaufler
2007-11-07  4:11                   ` Tetsuo Handa
2007-11-07  4:34                     ` Peter Dolding
2007-11-07  4:34                     ` Casey Schaufler
2007-10-30 18:42     ` Linux Security *Module* Framework (Was: LSM conversion to static interface) Jan Engelhardt
2007-10-30 19:14       ` Casey Schaufler
2007-10-30 19:50         ` Jan Engelhardt
2007-10-30 23:38       ` Peter Dolding
2007-10-31  0:16         ` david
2007-10-31  2:21           ` Peter Dolding
2007-10-31  3:43             ` Casey Schaufler
2007-10-31  5:08             ` david
2007-10-31  6:43             ` Crispin Cowan [this message]
2007-10-31  9:03               ` Peter Dolding
2007-10-31 10:10               ` Toshiharu Harada
2007-11-01  2:04                 ` Peter Dolding
2007-11-01  2:20                   ` Casey Schaufler
2007-11-01  2:51                     ` Peter Dolding
2007-11-01  7:17                       ` Jan Engelhardt
2007-11-01 11:49                         ` David Newall
2007-11-04  1:28                           ` Peter Dolding
2007-11-05  6:56                       ` Andrew Morgan
2007-11-05 13:29                         ` Serge E. Hallyn
2007-10-29 20:27 ` Casey Schaufler
  -- strict thread matches above, loose matches on Subject: below --
2007-10-29 10:01 Rob Meijer
2007-10-29 10:24 ` Crispin Cowan
2007-10-29 13:32   ` Peter Dolding
2007-10-18  2:18 LSM conversion to static interface Linus Torvalds
2007-10-19 20:26 ` Andreas Gruenbacher
2007-10-19 20:40   ` Linus Torvalds
2007-10-20 11:05     ` Jan Engelhardt
2007-10-20 22:57       ` James Morris
2007-10-23  4:09         ` LSM conversion to static interface [revert patch] Arjan van de Ven
2007-10-23  5:16           ` Chris Wright
2007-10-24  0:31             ` Jeremy Fitzhardinge
2007-10-24  5:06               ` Arjan van de Ven
2007-10-24 11:50                 ` Linux Security *Module* Framework (Was: LSM conversion to static interface Simon Arlott
2007-10-24 12:55                   ` Adrian Bunk
2007-10-24 18:11                     ` Linux Security *Module* Framework (Was: LSM conversion to static interface) Simon Arlott
2007-10-24 18:51                       ` Jan Engelhardt
2007-10-24 18:59                         ` Simon Arlott
2007-10-24 19:04                           ` Jan Engelhardt
2007-10-24 21:02                             ` David P. Quigley
2007-10-24 21:37                               ` Serge E. Hallyn
2007-10-24 21:51                                 ` Jan Engelhardt
2007-10-24 22:02                                   ` David P. Quigley
2007-10-24 23:13                                     ` Jan Engelhardt
2007-10-25  1:50                                 ` david
2007-10-25  3:50                                 ` Kyle Moffett
2007-10-24 21:42                               ` Jan Engelhardt
2007-10-24 21:58                               ` Casey Schaufler
2007-10-24 22:04                                 ` David P. Quigley
2007-10-25 11:38                               ` Simon Arlott
2007-10-24 20:18                         ` Crispin Cowan
2007-10-24 20:46                           ` Jan Engelhardt
2007-10-24 21:29                             ` Casey Schaufler
2007-10-24 22:31                       ` Adrian Bunk
2007-10-24 22:58                         ` Casey Schaufler
2007-10-24 23:32                           ` Adrian Bunk
2007-10-24 23:42                             ` Linus Torvalds
2007-10-25  0:41                               ` Chris Wright
2007-10-25  2:19                                 ` Arjan van de Ven
2007-10-30  3:37                                 ` Toshiharu Harada
2007-10-25  1:03                               ` Casey Schaufler
2007-10-25  0:23                           ` Chris Wright
2007-10-25  0:35                             ` Ray Lee
2007-10-25  1:26                               ` Peter Dolding
2007-10-25  1:41                               ` Alan Cox
2007-10-25  2:11                                 ` david
2007-10-25 18:17                                 ` Ray Lee
2007-10-25 22:21                                   ` Alan Cox
2007-10-26  3:45                                     ` david
2007-10-26  5:44                                       ` Peter Dolding
2007-10-27 18:29                                   ` Pavel Machek
2007-10-28 18:48                                     ` Hua Zhong
2007-10-28 19:05                                     ` Hua Zhong
2007-10-28 22:08                                 ` Crispin Cowan
2007-10-28 22:50                                   ` Alan Cox
2007-11-26 20:42                                     ` serge
2007-10-28 23:55                                   ` Peter Dolding
2007-10-29  5:12                                   ` Arjan van de Ven
2007-10-25  9:19                               ` Bernd Petrovitsch
2007-10-25 16:04                                 ` Ray Lee
2007-10-25 17:10                                   ` Arjan van de Ven
2007-10-30  9:41                                   ` Bernd Petrovitsch
2007-10-25  1:42                             ` Casey Schaufler
2007-10-27 18:22                               ` Pavel Machek
2007-10-30  3:23                               ` Toshiharu Harada
2007-10-30  8:40                                 ` Jan Engelhardt
2007-10-30  8:50                                   ` Crispin Cowan
2007-10-30  9:27                                     ` Jan Engelhardt
2007-10-30  9:21                                   ` Toshiharu Harada
2007-10-25 11:44                         ` Simon Arlott
2007-10-25 23:09                         ` Tilman Schmidt
2007-10-26  2:56                           ` Greg KH
2007-10-26  7:09                             ` Jan Engelhardt
2007-10-26 15:54                               ` Greg KH
2007-10-26  9:46                             ` Tilman Schmidt
2007-10-26 15:58                               ` Greg KH
2007-10-26 16:32                                 ` Simon Arlott
2007-10-26 23:26                               ` Adrian Bunk

Reply instructions:

You may reply publicly to this message via plain-text email
using any one of the following methods:

* Save the following mbox file, import it into your mail client,
  and reply-to-all from there: mbox

  Avoid top-posting and favor interleaved quoting:
  https://en.wikipedia.org/wiki/Posting_style#Interleaved_style

* Reply using the --to, --cc, and --in-reply-to
  switches of git-send-email(1):

  git send-email \
    --in-reply-to=472823FA.80303@crispincowan.com \
    --to=crispin@crispincowan.com \
    --cc=linux-kernel@vger.kernel.org \
    --cc=linux-security-module@vger.kernel.org \
    --cc=oiaohm@gmail.com \
    /path/to/YOUR_REPLY

  https://kernel.org/pub/software/scm/git/docs/git-send-email.html

* If your mail client supports setting the In-Reply-To header
  via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox