Re: [PATCH try #3] security: Convert LSM into a static interface

[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]

 



On Wed, 18 Jul 2007, Andrew Morton wrote:

> > The SECURITY_FRAMEWORK_VERSION macro has also been removed.
> 
> I'd like to understand who is (or claims to be) adversely affected by this
> change, and what their complaints (if any) will be.
> 
> Because I prefer my flamewars pre- rather than post-merge.

This was already discussed and resolved during previous postings of the 
patch.

In a nutshell, there is no safe way to unload an LSM.  The modular 
interface is thus unecessary and broken infrastructure.  It is used only 
by out-of-tree modules, which are often binary-only, illegal, abusive of 
the API and dangerous, e.g. silently re-vectoring SELinux.

Chris has already agreed to take the patch:  
http://lkml.org/lkml/2007/6/24/152


> aww man, you passed over an opportunity to fix vast amounts of coding style
> cruftiness.

GregKH-esque :-)

> <does whizzy things>
> 
> Here you go..

Thanks.


-- 
James Morris
<[email protected]>
-
To unsubscribe from this list: send the line "unsubscribe linux-kernel" in
the body of a message to [email protected]
More majordomo info at  http://vger.kernel.org/majordomo-info.html
Please read the FAQ at  http://www.tux.org/lkml/

[Index of Archives]     [Kernel Newbies]     [Netfilter]     [Bugtraq]     [Photo]     [Stuff]     [Gimp]     [Yosemite News]     [MIPS Linux]     [ARM Linux]     [Linux Security]     [Linux RAID]     [Video 4 Linux]     [Linux for the blind]     [Linux Resources]
  Powered by Linux