[kernel-hardening] Re: [PATCH RFC v2 1/3] LSM: Allow per LSM module per "struct task_struct" blob.
From: Kees Cook <hidden>
Date: 2017-04-11 04:43:48
Also in:
linux-api, lkml
From: Kees Cook <hidden>
Date: 2017-04-11 04:43:48
Also in:
linux-api, lkml
On Mon, Apr 10, 2017 at 1:00 PM, Djalal Harouni [off-list ref] wrote:
On Mon, Apr 10, 2017 at 9:26 PM, Casey Schaufler [off-list ref] wrote:quoted
I think that would be the prudent approach. There is still the possibility that blob sharing (or full stacking, if you prefer) won't be accepted any time soon.Ok Casey! I will wait for more feedback, and if other maintainers do not object, I will convert it back to rhashtables in next iterations making sure that it should be simple to convert later to a blob sharing mechanism.
Would it be possible just to add a single field to task_struct if this LSM is built in? I feel like rhashtables is a huge overhead when a single field is all that's needed. -Kees -- Kees Cook Pixel Security -- To unsubscribe from this list: send the line "unsubscribe linux-security-module" in the body of a message to majordomo at vger.kernel.org More majordomo info at http://vger.kernel.org/majordomo-info.html