LWN.net Logo

Wasn't LSM invented for this?

Wasn't LSM invented for this?

Posted Aug 28, 2008 10:34 UTC (Thu) by NAR (subscriber, #1313)
Parent article: TALPA strides forward

I don't know much about the kernel security, but doesn't the LSM provide these hooks already?


(Log in to post comments)

Wasn't LSM invented for this?

Posted Aug 29, 2008 0:22 UTC (Fri) by dlang (✭ supporter ✭, #313) [Link]

no, LSM can approve or deny access, but it doesn't have hooks to do notification on status change from clean->dirty, it also doesn't have the ability to record the results of a scan so that the file doesn't need to be scanned on access

Copyright © 2013, Eklektix, Inc.
Comments and public postings are copyrighted by their creators.
Linux is a registered trademark of Linus Torvalds