From mboxrd@z Thu Jan 1 00:00:00 1970 Return-Path: Received: from namei.org ([65.99.196.166]:59118 "EHLO namei.org" rhost-flags-OK-OK-OK-OK) by vger.kernel.org with ESMTP id S1726849AbeINXeK (ORCPT ); Fri, 14 Sep 2018 19:34:10 -0400 Date: Sat, 15 Sep 2018 04:18:14 +1000 (AEST) From: James Morris To: Casey Schaufler cc: Kees Cook , Paul Moore , linux-security-module , LKML , SE Linux , John Johansen , Tetsuo Handa , Stephen Smalley , "linux-fsdevel@vger.kernel.org" , Alexey Dobriyan , "Schaufler, Casey" Subject: Re: [PATCH 10/10] LSM: Blob sharing support for S.A.R.A and LandLock In-Reply-To: <5b983bba-049c-795a-3354-a2e8ab33cecf@schaufler-ca.com> Message-ID: References: <99cb1ae7-8881-eb9a-a8cb-a787abe454e1@schaufler-ca.com> <5b983bba-049c-795a-3354-a2e8ab33cecf@schaufler-ca.com> MIME-Version: 1.0 Content-Type: text/plain; charset=US-ASCII Sender: linux-fsdevel-owner@vger.kernel.org List-ID: On Thu, 13 Sep 2018, Casey Schaufler wrote: > On 9/13/2018 4:57 PM, Kees Cook wrote: > > On Thu, Sep 13, 2018 at 4:51 PM, Casey Schaufler wrote: > >> On 9/13/2018 4:06 PM, Kees Cook wrote: > >>> - what order should any stacking happen? Makefile? security=? > >> Makefile by default. > > Okay, if ordering is by Makefile and everyone dislikes my > > $lsm.enabled=0/1 thing, then these mean the same thing: > > > > security=selinux,tomoyo > > security=tomoyo,selinux > > > > i.e. order of security= is _ignored_ in favor of the Makefile ordering. > > No, I think that the two lines above should have a different > execution order. If we really need to specify multiple modules > at boot time that is what makes the most sense. Agreed. -- James Morris