Thread (77 messages) flat view 77 messages, 12 authors, 2011-05-29
STALE5586d

[PATCH 3/5] v2 seccomp_filters: Enable ftrace-based system call filtering

From: jmorris@namei.org (James Morris)
Date: 2011-05-17 02:24:34
Also in: linux-mips, linuxppc-dev

On Mon, 16 May 2011, Ingo Molnar wrote:
quoted
Not really.

Firstly, what is the security goal of these restrictions? [...]
To do what i described above? Namely:

 " Sandboxed code should only be allowed to open files in /home/sandbox/, /lib/
   and /usr/lib/ "
These are access rules, they don't really describe a high-level security 
goal.  How do you know it's ok to open everything in these directories?


- James
-- 
James Morris
[off-list ref]
Keyboard shortcuts
hback out one level
jnext message in thread
kprevious message in thread
ldrill in
Escclose help / fold thread tree
?toggle this help