From mboxrd@z Thu Jan 1 00:00:00 1970 Return-Path: Received: (majordomo@vger.kernel.org) by vger.kernel.org via listexpand id S1755894Ab2IBHhx (ORCPT ); Sun, 2 Sep 2012 03:37:53 -0400 Received: from cantor2.suse.de ([195.135.220.15]:34853 "EHLO mx2.suse.de" rhost-flags-OK-OK-OK-OK) by vger.kernel.org with ESMTP id S1752170Ab2IBHhw (ORCPT ); Sun, 2 Sep 2012 03:37:52 -0400 Date: Sun, 2 Sep 2012 09:37:40 +0200 (CEST) From: Jiri Kosina To: Kees Cook Cc: "Eric W. Biederman" , Eric Paris , Alan Cox , linux-kernel@vger.kernel.org, James Morris , Eric Paris , John Johansen , Dan Carpenter , Al Viro , linux-security-module@vger.kernel.org Subject: Re: [PATCH] security: unconditionally call Yama In-Reply-To: Message-ID: References: <20120831213126.GA19688@www.outflux.net> <20120831223908.4aa5574d@pyramind.ukuu.org.uk> <87ipbyfw9j.fsf@xmission.com> <87627ye7vh.fsf@xmission.com> User-Agent: Alpine 2.00 (LNX 1167 2008-08-23) MIME-Version: 1.0 Content-Type: TEXT/PLAIN; charset=US-ASCII Sender: linux-kernel-owner@vger.kernel.org List-ID: X-Mailing-List: linux-kernel@vger.kernel.org On Fri, 31 Aug 2012, Kees Cook wrote: > Given that several distros use (or want to use) Yama, I think that's > reason enough for this. I think it's important for us to take a > practical approach here, and having the big LSMs each hook Yama instead > of doing this in a single global place will make it needlessly > duplicated code. With my SUSE hat on, I would be really reluctant to enable config option in the distribution kernel that will make attaching gdb to running processess impossible without any further tuning (like sysctl/procfs knob to explicitly enable this feature). Thanks, -- Jiri Kosina SUSE Labs