Re: [PATCH v24 00/25] LSM: Module stacking for AppArmor

2021-02-02 Thread Casey Schaufler
On 2/2/2021 9:12 AM, Topi Miettinen wrote: > On 2.2.2021 17.30, Casey Schaufler wrote: >> On 2/2/2021 4:05 AM, Topi Miettinen wrote: >>> On 26.1.2021 18.40, Casey Schaufler wrote: This patchset provides the changes required for the AppArmor security module to stack safely with any other.

Re: [PATCH v24 00/25] LSM: Module stacking for AppArmor

2021-02-02 Thread Topi Miettinen
On 2.2.2021 17.30, Casey Schaufler wrote: On 2/2/2021 4:05 AM, Topi Miettinen wrote: On 26.1.2021 18.40, Casey Schaufler wrote: This patchset provides the changes required for the AppArmor security module to stack safely with any other. In my test, when kernel command line has apparmor before

Re: [PATCH v24 00/25] LSM: Module stacking for AppArmor

2021-02-02 Thread Casey Schaufler
On 2/2/2021 4:05 AM, Topi Miettinen wrote: > On 26.1.2021 18.40, Casey Schaufler wrote: >> This patchset provides the changes required for >> the AppArmor security module to stack safely with any other. > > In my test, when kernel command line has apparmor before selinux in lsm= > entry, the boot

Re: [PATCH v24 00/25] LSM: Module stacking for AppArmor

2021-02-02 Thread Topi Miettinen
On 26.1.2021 18.40, Casey Schaufler wrote: This patchset provides the changes required for the AppArmor security module to stack safely with any other. In my test, when kernel command line has apparmor before selinux in lsm= entry, the boot is not successful with enforcing=1: systemd[1]: Fail

[PATCH v24 00/25] LSM: Module stacking for AppArmor

2021-01-26 Thread Casey Schaufler
This patchset provides the changes required for the AppArmor security module to stack safely with any other. v24: Rebase to 5.11-rc1 Incorporate feedback from v23 - Address the IMA team's concerns about "label collisions". A label collision occurs when there is ambiguity about