From mboxrd@z Thu Jan 1 00:00:00 1970 Return-Path: Received: from bedivere.hansenpartnership.com ([66.63.167.143]:55296 "EHLO bedivere.hansenpartnership.com" rhost-flags-OK-OK-OK-OK) by vger.kernel.org with ESMTP id S1751963AbeA1RTk (ORCPT ); Sun, 28 Jan 2018 12:19:40 -0500 Message-ID: <1517159978.3082.32.camel@HansenPartnership.com> Subject: Re: [Lsf-pc] [LSF/MM TOPIC] fs-verity: file system-level integrity protection From: James Bottomley To: Theodore Ts'o Cc: Andreas Dilger , linux-fsdevel , lsf-pc@lists.linux-foundation.org Date: Sun, 28 Jan 2018 09:19:38 -0800 In-Reply-To: <20180128024604.GA12320@thunk.org> References: <20180125191152.GA11197@thunk.org> <1516927666.4082.25.camel@HansenPartnership.com> <20180126023054.GC31091@thunk.org> <1516942235.4082.52.camel@HansenPartnership.com> <20180126145856.GA2841@thunk.org> <1516985067.4000.10.camel@HansenPartnership.com> <20180126215540.GA23308@thunk.org> <275E5E86-635E-4D79-9AC9-3D24318EDDDF@dilger.ca> <1517069959.3012.13.camel@HansenPartnership.com> <20180128024604.GA12320@thunk.org> Content-Type: text/plain; charset="UTF-8" Mime-Version: 1.0 Content-Transfer-Encoding: 8bit Sender: linux-fsdevel-owner@vger.kernel.org List-ID: Just addressing this one comment from a process point of view; I'll come back to the technical part later. On Sat, 2018-01-27 at 21:46 -0500, Theodore Ts'o wrote: > (And then you can get some of the "the IMA people are insane" taint > on yourself.  :-) Can we please stop it with the "all IMA people are insane" mantra. I think we've created this problem, for all security people not just IMA, ourselves to some extent:  We think they're insane, so we don't listen to what they want.  They go and implement a complicated layering system to get what they need and we congratulate ourselves that they were insane because of the tasteless layering violations they've just committed.  The average security person, as ably created by us, has a mind that automatically thinks in terms of convoluted external layering, for which we just drive them further away. IMA has demonstrated a willingness to work with fs people to try to clean up the layering problems over the past year or so, including attending the last LSF/MM to discuss it.  Sure, they're going to have relapses into the layering mindset (fstype policies springs to mind), but the test is their willingness to listen to the correct way of doing things, which I think they're currently passing. Why don't you try working with them instead of starting from the a- priori axiom that you can't because they're insane?  They do have years of experience of what the industry is looking for in security terms, which we should make use of.  Doing security ourselves because we can't work with security people is a recipe for eventual tears. James