Re: [PATCH v2 security-next 1/4] security: Hornet LSM

2025-04-23 Thread Paul Moore
On Wed, Apr 23, 2025 at 10:12 AM James Bottomley wrote: > On Mon, 2025-04-21 at 13:12 -0700, Alexei Starovoitov wrote: > [...] > > Calling bpf_map_get() and > > map->ops->map_lookup_elem() from a module is not ok either. > > I don't understand this objection. The program just got passed in to > b

Re: [PATCH v2 security-next 1/4] security: Hornet LSM

2025-04-23 Thread James Bottomley
On Mon, 2025-04-21 at 13:12 -0700, Alexei Starovoitov wrote: [...] > Calling bpf_map_get() and > map->ops->map_lookup_elem() from a module is not ok either. I don't understand this objection. The program just got passed in to bpf_prog_load() as a set of attributes which, for a light skeleton, dir