Subject: Re: Integrating securelevel and kauth(9)
To: Elad Efrat <elad@NetBSD.org>
From: Bill Studenmund <wrstuden@netbsd.org>
List: tech-security
Date: 03/25/2006 10:05:39
--W/nzBZO5zC0uMSeA
Content-Type: text/plain; charset=us-ascii
Content-Disposition: inline
Content-Transfer-Encoding: quoted-printable

On Sat, Mar 25, 2006 at 12:56:53AM +0200, Elad Efrat wrote:
> Bill Studenmund wrote:
>=20
> > So my suggestion is to make LKMs change. Include a quick description of=
=20
> > how to change them (the define you gave was good) and a mapping of what=
=20
> > you can find now (if you were interested in making sure ioctl's could=
=20
> > happen, you make this call. If you are interested in the ability to acc=
ess=20
> > devices when others are busy, you make that call).
>=20
> I'll do that anyway, but the decision of requiring LKMs to change is not
> one that I can make. :) I am just suggesting possible solutions that we
> can use regardless of what we decide to do.

True, and I can't do it either. But voicing input can help make the=20
decision. :-)

Though if it all goes into 4.0, we will need the compat variable for at=20
least the 4.0 release.

Take care,

Bill

--W/nzBZO5zC0uMSeA
Content-Type: application/pgp-signature
Content-Disposition: inline

-----BEGIN PGP SIGNATURE-----
Version: GnuPG v1.2.3 (NetBSD)

iD8DBQFEJYZzWz+3JHUci9cRArywAJ4zmVFG/Q++KV9wJJ5vUt0aHw/SlgCgjD00
hY5IvpBTTeg4N5igvaOU9iA=
=Ax9s
-----END PGP SIGNATURE-----

--W/nzBZO5zC0uMSeA--