Thread (77 messages) 77 messages, 12 authors, 2011-05-29
STALE5469d

[PATCH 3/5] v2 seccomp_filters: Enable ftrace-based system call filtering

From: jmorris@namei.org (James Morris)
Date: 2011-05-13 00:18:52
Also in: linux-mips, linuxppc-dev

On Thu, 12 May 2011, Ingo Molnar wrote:
Funnily enough, back then you wrote this:

  " I'm concerned that we're seeing yet another security scheme being designed on 
    the fly, without a well-formed threat model, and without taking into account 
    lessons learned from the seemingly endless parade of similar, failed schemes. "

so when and how did your opinion of this scheme turn from it being an "endless 
parade of failed schemes" to it being a "well-defined and readily 
understandable feature"? :-)
When it was defined in a way which limited its purpose to reducing the 
attack surface of the sycall interface.


- James
-- 
James Morris
[off-list ref]
Keyboard shortcuts
hback out one level
jnext message in thread
kprevious message in thread
ldrill in
Escclose help / fold thread tree
?toggle this help