Follow @Openwall on Twitter for new release announcements and other news
[<prev] [next>] [day] [month] [year] [list]
Date: Sun, 12 Jun 2011 06:56:34 +0400
From: Solar Designer <solar@...nwall.com>
To: kernel-hardening@...ts.openwall.com
Subject: link & FIFO hardening

Vasiliy, Kees -

Vasiliy - in your "overview of grsecurity and -ow patches":

http://www.openwall.com/lists/owl-dev/2011/04/23/1

you wrote:

> GRKERNSEC_LINK [+]
> GRKERNSEC_FIFO [+]
> GRKERNSEC_HARDEN_PTRACE [+]
> 
>     There is YAMA LSM for mainline, implementing these features.  It is not
>     yet applied, but Kees Cook does his best to push it.  For RHEL6/OpenVZ
>     YAMA should be OK (with Ubuntu's forcing scheme), with minor
>     synchorization changes.

What's the status on this (for mainline)?  I regard the link (both
symlink and hard link) and FIFO restrictions as a priority, compared to
some other things we'll be working on.  (In general, I want us to have a
full set of whatever was in 2.4.x-ow merged sooner rather than later.)

Thanks,

Alexander

Powered by blists - more mailing lists

Confused about mailing lists and their use? Read about mailing lists on Wikipedia and check out these guidelines on proper formatting of your messages.