LSM stacking (again)
LSM stacking (again)
Posted Jun 24, 2010 16:26 UTC (Thu) by bronson (subscriber, #4806)In reply to: LSM stacking (again) by Cyberax
Parent article: LSM stacking (again)
So and AppArmor and SELinux and Smack and Tomoyo would need to be written with all possible permutations in mind? That sounds absolutely hellish to analyze and test. Remember, we're talking about security here -- failure is far worse than a kernel panic.
Maybe it would be possible if all projects split their code into completely isolated modules: AppArmor-Network, AppArmor-Filesystem, etc. No interaction allowed between the Network and Filesystem modules. But I don't think that would meet SELinux's needs.
