Re: [AppArmor 37/41] AppArmor: Main Part



On Thursday 12 April 2007 12:37, Alan Cox wrote:
The proc file system may not be mounted at /proc. There are environments
where this is done for good reason (eg not wanting the /proc info exposed
to a low trust environment). Another is when FUSE is providing an
arbitrated proc either by merging across clusters or by removing stuff.
[...]
Why can't this be done in the profile itself to avoid kernel special case
uglies and inflexibility ?

Good points. I'm in fact not sure how this could have been missed, and indeed
it makes more sense to put this in profiles.

Thanks,
Andreas
-
To unsubscribe from this list: send the line "unsubscribe linux-kernel" in
the body of a message to majordomo@xxxxxxxxxxxxxxx
More majordomo info at http://vger.kernel.org/majordomo-info.html
Please read the FAQ at http://www.tux.org/lkml/



Relevant Pages

  • Re: Awareness of Nottales scale relativity work
    ... reason :-) ... the rotation profile of thin disk galaxies ... understand the nuts and bolts of elliptical integrals that were first ... passed through a symbolic math package. ...
    (sci.physics.research)
  • Re: Use the Additional DC when PDC is down
    ... I have known users who have used the sysvol as a replication point, ... you mentioned I wouldn't recommend it and that is the reason I didn't in my ... > I also have 2 dcs in my home lan with a profile share on one and want ...
    (microsoft.public.win2000.active_directory)
  • Re: accidently deleted COMPUTER in server manager
    ... It's one of those things that usually works, but when it doesn't for some reason, you're basically out of luck. ... Deleted computer, arghh ... you can have users log in to create a profile and then copy over the old profile information. ...
    (microsoft.public.windows.server.sbs)
  • Re: Night Light: Utility Bike/Short Haul?
    ... Yeah, I think I've read most of the threads. ... But nobody seems to have spelled out the functional diff between ... Assuming there's a reason that a jogger is advised to run facing ... bike moving at the same or slower speed with the same profile ...
    (rec.bicycles.tech)
  • Re: DUnit TestCase wizard is useless
    ... I'll profile (performance, memory, code coverage) the unit tests ... but have reason to believe is doing something really stupid ...
    (borland.public.delphi.non-technical)