1 May 2006 01:07
Re: another kconfig target for building monolithic kernel (for security) ?
<devzero <at> web.de>
2006-04-30 23:07:14 GMT
2006-04-30 23:07:14 GMT
hello !
thanks for help - i found that there seems another way for securing /dev/{k}mem (at least in recent kernels)
- the docomentation for the "BSD Secure Levels Linux Security Module" (at Documentation/seclvl.txt) tells:
Level 1 (Default):
- /dev/mem and /dev/kmem are read-only
- IMMUTABLE and APPEND extended attributes, if set, may not be unset
- Cannot load or unload kernel modules
- Cannot write directly to a mounted block device
- Cannot perform raw I/O operations
- Cannot perform network administrative tasks
- Cannot setuid any file
so - no need for compiling a static/monolithic kernel anymore !?
regards
roland
> -----Ursprüngliche Nachricht-----
> Von: Nix <nix <at> esperi.org.uk>
> Gesendet: 30.04.06 12:57:49
> An: Arjan van de Ven <arjan <at> infradead.org>
> CC: davej <at> redhat.com, linux-kernel <at> vger.kernel.org
> Betreff: Re: another kconfig target for building monolithic kernel (for security) ?
> On 29 Apr 2006, Arjan van de Ven prattled cheerily:
> > On Sat, 2006-04-29 at 12:43 -0400, Dave Jones wrote:
> >> On Sat, Apr 29, 2006 at 03:03:55PM +0200, devzero <at> web.de wrote:
> >>
(Continue reading)
> > > >
> > > > ...adding more dependencies to how vm/blockdevs work. I'd say current
> > > > code is complex enough...
> > >
> > > Well, why don't we see the patch? If it's too complex, we can just
RSS Feed