Jan Engelhardt wrote: > I do have a pseudo LSM called "multiadm" at > http://freshmeat.net/p/multiadm/ , quoting:
> Policy is dead simple since it is based on UIDs. The UID ranges can be > set on module load time or during runtime (sysfs params). This LSM is > basically grants extra rights unlike most other LSMs[1], which is why > modprobe makes much more sense here. (It also does not have to do any > security labelling that would require it to be loaded at boot time > already.) But his is against LSM design (and first agreements about LSM): LSM can deny rights, but it should not give extra permissions or bypass standard unix permissions. ciao cate - To unsubscribe from this list: send the line "unsubscribe linux-kernel" in the body of a message to [EMAIL PROTECTED] More majordomo info at http://vger.kernel.org/majordomo-info.html Please read the FAQ at http://www.tux.org/lkml/