Thread (18 messages) 18 messages, 5 authors, 2019-10-11

Re: [PATCH RFC] perf_event: Add support for LSM and SELinux checks

From: James Morris <jmorris@namei.org>
Date: 2019-10-10 02:45:08
Also in: bpf, lkml, selinux

On Wed, 9 Oct 2019, Casey Schaufler wrote:
On 10/9/2019 3:14 PM, James Morris wrote:
quoted
On Wed, 9 Oct 2019, Casey Schaufler wrote:
quoted
Please consider making the perf_alloc security blob maintained
by the infrastructure rather than the individual modules. This
will save it having to be changed later.
Is anyone planning on using this with full stacking?

If not, we don't need the extra code & complexity. Stacking should only 
cover what's concretely required by in-tree users.
I don't believe it's any simpler for SELinux to do the allocation
than for the infrastructure to do it. I don't see anyone's head
exploding over the existing infrastructure allocation of blobs.
We're likely to want it at some point, so why not avoid the hassle
and delay by doing it the "new" way up front?
Because it is not necessary.

-- 
James Morris
[off-list ref]
Keyboard shortcuts
hback out one level
jnext message in thread
kprevious message in thread
ldrill in
Escclose help / fold thread tree
?toggle this help