Language Selection

English French German Italian Portuguese Spanish

Kernel space: Linux security non-modules and AppArmor

Filed under
Linux

Long-time LWN readers will know that the Linux security module (LSM) API is controversial at best. To many, it has failed in its purpose, which is enabling the development of competing approaches to hardened Linux system; the only significant in-tree security module remains SELinux. Meanwhile, the LSM interface is easily abused; since it allows the insertion of hooks into almost any system operation of interest, it can be used by other modules to provide non-security functionality. The LSM symbols are mostly exported GPL-only, but it is still possible for binary-only modules to abuse the LSM operations - and, apparently, some have done so.

SELinux hacker James Morris has been pondering this issue recently; he has also noticed that the in-tree security modules (SELinux and the small module implementing capabilities) cannot be unloaded. So, he asked, why implement a modular interface at all?

There have been a few complaints, but, from the author's point of view, it does not seem like anybody has come up with a compelling reason why it must be possible to unload security modules.

One such module is AppArmor - the GPL-licensed security mechanism distributed by Novell.

More Here.




More in Tux Machines

Eight great Linux gifts for the holiday season

Do you want to give your techie friend a very Linux holiday season? Sure you do! Here are some suggestion to brighten your favorite Tux fan's day. Read more Also: More Random Gift Ideas For Linux Enthusiasts & Others Into Tech Which open source gift is at the top of your holiday wish list?

Ubuntu-Based ExTiX OS Updated for Intel Compute Sticks with Improved Installer

GNU/Linux developer Arne Exton announced this past weekend the release of an updated build of his Ubuntu-based ExTiX Linux distribution for Intel Compute Stick devices. Last month, we reported on the initial availability of a port of the ExTiX operating system for Intel Compute Sticks, boasting the lightweight and modern LXQt 0.10.0 desktop environment and powered by the latest Linux 4.8 kernel, tweaked by Arne Exton for Intel Atom processors. And now, ExTiX Build 161203 is out as a drop-in replacement for Build 161119, bringing a much-improved Ubiquity graphics installer that should no longer crash, as several users who attempted to install the Ubuntu-based GNU/Linux distro on their Intel Compute Stick devices reported. Read more Also: Debian-Based SparkyLinux 4.5 Brings Support for exFAT Filesystems, systemd 232 4MLinux 20.1 Linux Distro Released with Kernel 4.4.34 LTS to Restore PAE Support

Today in Techrights

Canonical Releases Snapcraft 2.23 Snap Creator for Ubuntu 16.04 LTS and 16.10

Canonical's Snappy development team have released a new maintenance version of the Snapcraft 2.x tool that lets applications developers package their apps as Snap packages for Ubuntu and other GNU/Linux distributions that support Snaps. Read more