Thread (77 messages) flat view 77 messages, 12 authors, 2011-05-29
STALE5586d

[PATCH 3/5] v2 seccomp_filters: Enable ftrace-based system call filtering

From: jmorris@namei.org (James Morris)
Date: 2011-05-17 13:29:36
Also in: linux-mips, linuxppc-dev

On Tue, 17 May 2011, Ingo Molnar wrote:
I'm not sure i get your point.
Your example was not complete as described.  After an apparently simple 
specification, you've since added several qualifiers and assumptions, and 
I still doubt that it's complete.

A higher level goal would look like

"Allow a sandbox app access only to approved resources, to contain the 
effects of flaws in the app", or similar.

Note that this includes a threat model (remote attacker taking control of 
the app) and a general and fully stated strategy for dealing with it.
Keyboard shortcuts
hback out one level
jnext message in thread
kprevious message in thread
ldrill in
Escclose help / fold thread tree
?toggle this help