logo       

security_task_lookup plus bsdjail patches: msg#00003

linux.kernel.lsm

Subject: security_task_lookup plus bsdjail patches

Attached are a BSD Jail patch without the network device hooks :(, but using
the new security_task_lookup hook to hide /proc/<pid> as much as possible.
The network ioctl abuse was also removed, leaving a jail user with only
`cat /proc/$$/attr/current` to list the valid IP addresses.

Hopefully this will be going to LKML next.

Comments much appreciated.

thanks,
-serge

Attachment: tasklookup-sep04.diff
Description: Text document

Attachment: jail-sep04.diff
Description: Text document

<Prev in Thread] Current Thread [Next in Thread>
Google Custom Search

News | FAQ | advertise