Critical Linux security API is still a kludge (Inquirer)
Posted Oct 23, 2006 16:30 UTC (Mon) by
nix (subscriber, #2304)
In reply to:
Critical Linux security API is still a kludge (Inquirer) by AJWM
Parent article:
Critical Linux security API is still a kludge (Inquirer)
The LSM API intentionally does not stack. Stacking LSM modules that only restrict access is *probably* safe, but how can you be sure that the consequences of ANDing two unrelated modules' constraints together is still secure?
(This annoys me, too, but the reasoning for banning stacking is an absolute killer...)
(
Log in to post comments)