SGX vs LSM (Re: [PATCH v20 00/28] Intel SGX1 support)
Jarkko Sakkinen
jarkko.sakkinen at linux.intel.com
Wed May 22 13:10:04 UTC 2019
On Tue, May 21, 2019 at 03:24:18PM +0000, Jethro Beekman wrote:
> On 2019-05-21 08:19, Jarkko Sakkinen wrote:
> > We could even disallow mmap() before EINIT done.
> This would be extremely annoying in software because now you have to save
> the all the page permissions somewhere between EADD and mprotect.
Actually you don't have to use mprotect anymore that much.
You can just do multiple mmap's even with v20 after EINIT, one
for each region (albeit it does not enforce above).
/Jarkko
More information about the Linux-security-module-archive
mailing list