From mboxrd@z Thu Jan 1 00:00:00 1970 Return-Path: Received: from mail-yw1-f66.google.com ([209.85.161.66]:38511 "EHLO mail-yw1-f66.google.com" rhost-flags-OK-OK-OK-OK) by vger.kernel.org with ESMTP id S1726969AbeINFPC (ORCPT ); Fri, 14 Sep 2018 01:15:02 -0400 Received: by mail-yw1-f66.google.com with SMTP id n21-v6so1938393ywh.5 for ; Thu, 13 Sep 2018 17:03:16 -0700 (PDT) Received: from mail-yb1-f181.google.com (mail-yb1-f181.google.com. [209.85.219.181]) by smtp.gmail.com with ESMTPSA id x184-v6sm4895902ywx.75.2018.09.13.17.03.14 for (version=TLS1_2 cipher=ECDHE-RSA-AES128-GCM-SHA256 bits=128/128); Thu, 13 Sep 2018 17:03:15 -0700 (PDT) Received: by mail-yb1-f181.google.com with SMTP id t71-v6so4059079ybi.7 for ; Thu, 13 Sep 2018 17:03:14 -0700 (PDT) MIME-Version: 1.0 In-Reply-To: References: <99cb1ae7-8881-eb9a-a8cb-a787abe454e1@schaufler-ca.com> From: Kees Cook Date: Thu, 13 Sep 2018 17:03:12 -0700 Message-ID: Subject: Re: [PATCH 10/10] LSM: Blob sharing support for S.A.R.A and LandLock To: Casey Schaufler Cc: Paul Moore , linux-security-module , James Morris , LKML , SE Linux , John Johansen , Tetsuo Handa , Stephen Smalley , "linux-fsdevel@vger.kernel.org" , Alexey Dobriyan , "Schaufler, Casey" Content-Type: text/plain; charset="UTF-8" Sender: linux-fsdevel-owner@vger.kernel.org List-ID: On Thu, Sep 13, 2018 at 4:51 PM, Casey Schaufler wrote: > On 9/13/2018 4:06 PM, Kees Cook wrote: >> If security= is >> specified, all other major LSMs are disabled (i.e. it is not possible >> to switch between SELinux/AppArmor/SMACK without also disabling >> TOMOYO). > > Correct. If we assume patch 10 is the way forward, how could we go about fixing this specific problem? -Kees -- Kees Cook Pixel Security