[PATCH v21 07/12] landlock: Support filesystem access-control

Mickaël Salaün mic at digikod.net
Wed Oct 14 19:13:42 UTC 2020


On 14/10/2020 20:52, Mickaël Salaün wrote:
> 
> On 14/10/2020 20:07, James Morris wrote:
>> On Thu, 8 Oct 2020, Mickaël Salaün wrote:
>>
>>> +config ARCH_EPHEMERAL_STATES
>>> +	def_bool n
>>> +	help
>>> +	  An arch should select this symbol if it does not keep an internal kernel
>>> +	  state for kernel objects such as inodes, but instead relies on something
>>> +	  else (e.g. the host kernel for an UML kernel).
>>> +
>>
>> This is used to disable Landlock for UML, correct?
> 
> Yes
> 
>> I wonder if it could be 
>> more specific: "ephemeral states" is a very broad term.
>>
>> How about something like ARCH_OWN_INODES ?
> 
> Sounds good. We may need add new ones (e.g. for network socket, UID,
> etc.) in the future though.
> 

Because UML is the exception here, it would be more convenient to keep
the inverted semantic. What about ARCH_NO_OWN_INODES or
ARCH_EPHEMERAL_INODES?



More information about the Linux-security-module-archive mailing list