Thread (77 messages) flat view 77 messages, 12 authors, 2011-05-29
STALE5571d

Re: [PATCH 3/5] v2 seccomp_filters: Enable ftrace-based system call filtering

From: James Morris <jmorris@namei.org>
Date: 2011-05-12 11:44:15
Also in: linux-arm-kernel, linux-mips

On Thu, 12 May 2011, Ingo Molnar wrote:
2) Why should this concept not be made available wider, to allow the 
   restriction of not just system calls but other security relevant components 
   of the kernel as well?
Because the aim of this is to reduce the attack surface of the syscall 
interface.

LSM is the correct level of abstraction for general security mediation, 
because it allows you to take into account all relevant security 
information in a race-free context.

   This too, if you approach the problem via the events code, will be a natural 
   end result, while if you approach it from the seccomp prctl angle it will be
   a limited hack only.
I'd say it's a well-defined and readily understandable feature.


- James
-- 
James Morris
[off-list ref]
Keyboard shortcuts
hback out one level
jnext message in thread
kprevious message in thread
ldrill in
Escclose help / fold thread tree
?toggle this help