From mboxrd@z Thu Jan 1 00:00:00 1970 From: Kees Cook Subject: Re: [kernel-hardening] Re: [PATCH v3 1/2] modules:capabilities: automatic module loading restriction Date: Thu, 20 Apr 2017 14:28:59 -0700 Message-ID: References: <1492640420-27345-1-git-send-email-tixxdz@gmail.com> <1492640420-27345-2-git-send-email-tixxdz@gmail.com> <1492654942.31767.21.camel@decadent.org.uk> <1492700543.31767.23.camel@decadent.org.uk> Mime-Version: 1.0 Content-Type: text/plain; charset=UTF-8 Return-path: In-Reply-To: Sender: linux-api-owner-u79uwXL29TY76Z2rM5mHXA@public.gmane.org To: Djalal Harouni Cc: Ben Hutchings , Linux Kernel Mailing List , Andy Lutomirski , Andrew Morton , "Serge E. Hallyn" , "kernel-hardening-ZwoEplunGu1jrUoiu81ncdBPR1lH4CV8@public.gmane.org" , LSM List , Linux API , Dongsu Park , Casey Schaufler , James Morris , Paul Moore , Tetsuo Handa , Greg Kroah-Hartman , Jonathan Corbet , Jessica Yu , Rusty Russell , Arnaldo Carvalho de Melo List-Id: linux-api@vger.kernel.org On Thu, Apr 20, 2017 at 1:39 PM, Djalal Harouni wrote: > On Thu, Apr 20, 2017 at 5:02 PM, Ben Hutchings wrote: >> On Thu, 2017-04-20 at 14:44 +0200, Djalal Harouni wrote: >>> > On Thu, Apr 20, 2017 at 4:22 AM, Ben Hutchings wrote: >>> > On Thu, 2017-04-20 at 00:20 +0200, Djalal Harouni wrote: >>> > [...] > [...] >>> modules_disabled is too restrictive and once set it can't be changed, >>> maybe that's why not all users use it. >>> >>> With modules_disabled=0 and modules_autoload=2 >> [...] >> >> Hmm, OK. How about naming this modules_autoload_mode, then, so that >> it's obviously not a boolean? > > Yes that's fine by me, kees already suggested to rename it to > "modules_autoload" I can change it to that if it's the best > suggestion! That's fine by me. -Kees -- Kees Cook Pixel Security