Re: [RFC PATCH v3 00/13] Clavis LSM

2025-03-11 Thread Paul Moore
On March 6, 2025 5:29:36 PM Eric Snowberg wrote: On Mar 5, 2025, at 6:12 PM, Paul Moore wrote: On Wed, Mar 5, 2025 at 4:30 PM Eric Snowberg wrote: On Mar 4, 2025, at 5:23 PM, Paul Moore wrote: On Tue, Mar 4, 2025 at 9:47 AM Eric Snowberg wrote: On Mar 3, 2025, at 3:40 PM, Paul Moore wrot

Re: [RFC PATCH v3 00/13] Clavis LSM

2025-03-06 Thread Eric Snowberg
> On Mar 5, 2025, at 6:12 PM, Paul Moore wrote: > > On Wed, Mar 5, 2025 at 4:30 PM Eric Snowberg wrote: >>> On Mar 4, 2025, at 5:23 PM, Paul Moore wrote: >>> On Tue, Mar 4, 2025 at 9:47 AM Eric Snowberg >>> wrote: > On Mar 3, 2025, at 3:40 PM, Paul Moore wrote: > On Fri, Feb 28, 20

Re: [RFC PATCH v3 00/13] Clavis LSM

2025-03-05 Thread Paul Moore
On Wed, Mar 5, 2025 at 4:30 PM Eric Snowberg wrote: > > On Mar 4, 2025, at 5:23 PM, Paul Moore wrote: > > On Tue, Mar 4, 2025 at 9:47 AM Eric Snowberg > > wrote: > >>> On Mar 3, 2025, at 3:40 PM, Paul Moore wrote: > >>> On Fri, Feb 28, 2025 at 12:52 PM Eric Snowberg > >>> wrote: > > On F

Re: [RFC PATCH v3 00/13] Clavis LSM

2025-03-05 Thread Eric Snowberg
> On Mar 4, 2025, at 5:23 PM, Paul Moore wrote: > > On Tue, Mar 4, 2025 at 9:47 AM Eric Snowberg wrote: >>> On Mar 3, 2025, at 3:40 PM, Paul Moore wrote: >>> On Fri, Feb 28, 2025 at 12:52 PM Eric Snowberg >>> wrote: > On Feb 28, 2025, at 9:14 AM, Paul Moore wrote: > On Fri, Feb 28,

Re: [RFC PATCH v3 00/13] Clavis LSM

2025-03-04 Thread Paul Moore
On Tue, Mar 4, 2025 at 5:25 PM Jarkko Sakkinen wrote: > On Mon, Mar 03, 2025 at 05:40:54PM -0500, Paul Moore wrote: > > On Fri, Feb 28, 2025 at 12:52 PM Eric Snowberg > > wrote: > > > > On Feb 28, 2025, at 9:14 AM, Paul Moore wrote: > > > > On Fri, Feb 28, 2025 at 9:09 AM Mimi Zohar wrote: > >

Re: [RFC PATCH v3 00/13] Clavis LSM

2025-03-04 Thread Paul Moore
On Tue, Mar 4, 2025 at 9:20 PM Mimi Zohar wrote: > On Tue, 2025-03-04 at 21:09 -0500, Paul Moore wrote: > > On Tue, Mar 4, 2025 at 8:50 PM Mimi Zohar wrote: > > > On Tue, 2025-03-04 at 19:19 -0500, Paul Moore wrote: > > > > On Tue, Mar 4, 2025 at 7:54 AM Mimi Zohar wrote: > > > > > On Mon, 2025-

Re: [RFC PATCH v3 00/13] Clavis LSM

2025-03-04 Thread Mimi Zohar
On Tue, 2025-03-04 at 21:09 -0500, Paul Moore wrote: > On Tue, Mar 4, 2025 at 8:50 PM Mimi Zohar wrote: > > On Tue, 2025-03-04 at 19:19 -0500, Paul Moore wrote: > > > On Tue, Mar 4, 2025 at 7:54 AM Mimi Zohar wrote: > > > > On Mon, 2025-03-03 at 17:38 -0500, Paul Moore wrote: > > > > > On Fri, Fe

Re: [RFC PATCH v3 00/13] Clavis LSM

2025-03-04 Thread Paul Moore
On Tue, Mar 4, 2025 at 8:50 PM Mimi Zohar wrote: > On Tue, 2025-03-04 at 19:19 -0500, Paul Moore wrote: > > On Tue, Mar 4, 2025 at 7:54 AM Mimi Zohar wrote: > > > On Mon, 2025-03-03 at 17:38 -0500, Paul Moore wrote: > > > > On Fri, Feb 28, 2025 at 12:19 PM Mimi Zohar wrote: > > > > > On Fri, 202

Re: [RFC PATCH v3 00/13] Clavis LSM

2025-03-04 Thread Mimi Zohar
On Tue, 2025-03-04 at 19:19 -0500, Paul Moore wrote: > On Tue, Mar 4, 2025 at 7:54 AM Mimi Zohar wrote: > > On Mon, 2025-03-03 at 17:38 -0500, Paul Moore wrote: > > > On Fri, Feb 28, 2025 at 12:19 PM Mimi Zohar wrote: > > > > On Fri, 2025-02-28 at 11:14 -0500, Paul Moore wrote: > > > > > On Fri,

Re: [RFC PATCH v3 00/13] Clavis LSM

2025-03-04 Thread Jarkko Sakkinen
On Tue, Mar 04, 2025 at 07:25:13PM -0500, Paul Moore wrote: > On Tue, Mar 4, 2025 at 5:25 PM Jarkko Sakkinen wrote: > > On Mon, Mar 03, 2025 at 05:40:54PM -0500, Paul Moore wrote: > > > On Fri, Feb 28, 2025 at 12:52 PM Eric Snowberg > > > wrote: > > > > > On Feb 28, 2025, at 9:14 AM, Paul Moore

Re: [RFC PATCH v3 00/13] Clavis LSM

2025-03-04 Thread Paul Moore
On Tue, Mar 4, 2025 at 9:47 AM Eric Snowberg wrote: > > On Mar 3, 2025, at 3:40 PM, Paul Moore wrote: > > On Fri, Feb 28, 2025 at 12:52 PM Eric Snowberg > > wrote: > >>> On Feb 28, 2025, at 9:14 AM, Paul Moore wrote: > >>> On Fri, Feb 28, 2025 at 9:09 AM Mimi Zohar wrote: > On Thu, 2025-

Re: [RFC PATCH v3 00/13] Clavis LSM

2025-03-04 Thread Paul Moore
On Tue, Mar 4, 2025 at 7:54 AM Mimi Zohar wrote: > On Mon, 2025-03-03 at 17:38 -0500, Paul Moore wrote: > > On Fri, Feb 28, 2025 at 12:19 PM Mimi Zohar wrote: > > > On Fri, 2025-02-28 at 11:14 -0500, Paul Moore wrote: > > > > On Fri, Feb 28, 2025 at 9:09 AM Mimi Zohar wrote: > > > > > On Thu, 20

Re: [RFC PATCH v3 00/13] Clavis LSM

2025-03-04 Thread Jarkko Sakkinen
On Mon, Mar 03, 2025 at 05:40:54PM -0500, Paul Moore wrote: > On Fri, Feb 28, 2025 at 12:52 PM Eric Snowberg > wrote: > > > On Feb 28, 2025, at 9:14 AM, Paul Moore wrote: > > > On Fri, Feb 28, 2025 at 9:09 AM Mimi Zohar wrote: > > >> On Thu, 2025-02-27 at 17:22 -0500, Paul Moore wrote: > > >>>

Re: [RFC PATCH v3 00/13] Clavis LSM

2025-03-04 Thread Eric Snowberg
> On Mar 3, 2025, at 3:40 PM, Paul Moore wrote: > > On Fri, Feb 28, 2025 at 12:52 PM Eric Snowberg > wrote: >>> On Feb 28, 2025, at 9:14 AM, Paul Moore wrote: >>> On Fri, Feb 28, 2025 at 9:09 AM Mimi Zohar wrote: On Thu, 2025-02-27 at 17:22 -0500, Paul Moore wrote: > > I'd sti

Re: [RFC PATCH v3 00/13] Clavis LSM

2025-03-04 Thread Mimi Zohar
On Mon, 2025-03-03 at 17:38 -0500, Paul Moore wrote: > On Fri, Feb 28, 2025 at 12:19 PM Mimi Zohar wrote: > > On Fri, 2025-02-28 at 11:14 -0500, Paul Moore wrote: > > > On Fri, Feb 28, 2025 at 9:09 AM Mimi Zohar wrote: > > > > On Thu, 2025-02-27 at 17:22 -0500, Paul Moore wrote: > > ... > > > O

Re: [RFC PATCH v3 00/13] Clavis LSM

2025-03-03 Thread Paul Moore
On Fri, Feb 28, 2025 at 12:52 PM Eric Snowberg wrote: > > On Feb 28, 2025, at 9:14 AM, Paul Moore wrote: > > On Fri, Feb 28, 2025 at 9:09 AM Mimi Zohar wrote: > >> On Thu, 2025-02-27 at 17:22 -0500, Paul Moore wrote: > >>> > >>> I'd still also like to see some discussion about moving towards the

Re: [RFC PATCH v3 00/13] Clavis LSM

2025-03-03 Thread Paul Moore
On Fri, Feb 28, 2025 at 12:19 PM Mimi Zohar wrote: > On Fri, 2025-02-28 at 11:14 -0500, Paul Moore wrote: > > On Fri, Feb 28, 2025 at 9:09 AM Mimi Zohar wrote: > > > On Thu, 2025-02-27 at 17:22 -0500, Paul Moore wrote: ... > Ok, let's go through different scenarios to see if it would scale. > >

Re: [RFC PATCH v3 00/13] Clavis LSM

2025-03-01 Thread Jarkko Sakkinen
On Thu, Feb 27, 2025 at 03:41:18PM -0500, Mimi Zohar wrote: > On Mon, 2025-01-06 at 17:15 +, Eric Snowberg wrote: > > > > > On Jan 5, 2025, at 8:40 PM, Paul Moore wrote: > > > > > > On Fri, Jan 3, 2025 at 11:48 PM Paul Moore wrote: > > > > > > > > Regardless, back to Clavis ... reading qui

Re: [RFC PATCH v3 00/13] Clavis LSM

2025-02-28 Thread Jarkko Sakkinen
On Thu, Feb 27, 2025 at 05:22:22PM -0500, Paul Moore wrote: > On Thu, Feb 27, 2025 at 3:41 PM Mimi Zohar wrote: > > On Mon, 2025-01-06 at 17:15 +, Eric Snowberg wrote: > > > > On Jan 5, 2025, at 8:40 PM, Paul Moore wrote: > > > > On Fri, Jan 3, 2025 at 11:48 PM Paul Moore wrote: > > > > > >

Re: [RFC PATCH v3 00/13] Clavis LSM

2025-02-28 Thread Eric Snowberg
> On Feb 28, 2025, at 9:14 AM, Paul Moore wrote: > > On Fri, Feb 28, 2025 at 9:09 AM Mimi Zohar wrote: >> On Thu, 2025-02-27 at 17:22 -0500, Paul Moore wrote: >>> >>> I'd still also like to see some discussion about moving towards the >>> addition of keyrings oriented towards usage instead of

Re: [RFC PATCH v3 00/13] Clavis LSM

2025-02-28 Thread Mimi Zohar
On Fri, 2025-02-28 at 11:14 -0500, Paul Moore wrote: > On Fri, Feb 28, 2025 at 9:09 AM Mimi Zohar wrote: > > On Thu, 2025-02-27 at 17:22 -0500, Paul Moore wrote: > > > > > > I'd still also like to see some discussion about moving towards the > > > addition of keyrings oriented towards usage inste

Re: [RFC PATCH v3 00/13] Clavis LSM

2025-02-28 Thread Paul Moore
On Fri, Feb 28, 2025 at 9:09 AM Mimi Zohar wrote: > On Thu, 2025-02-27 at 17:22 -0500, Paul Moore wrote: > > > > I'd still also like to see some discussion about moving towards the > > addition of keyrings oriented towards usage instead of limiting > > ourselves to keyrings that are oriented on th

Re: [RFC PATCH v3 00/13] Clavis LSM

2025-02-28 Thread Mimi Zohar
On Thu, 2025-02-27 at 17:22 -0500, Paul Moore wrote: > On Thu, Feb 27, 2025 at 3:41 PM Mimi Zohar wrote: > > On Mon, 2025-01-06 at 17:15 +, Eric Snowberg wrote: > > > > On Jan 5, 2025, at 8:40 PM, Paul Moore wrote: > > > > On Fri, Jan 3, 2025 at 11:48 PM Paul Moore wrote: > > > > > > > > >

Re: [RFC PATCH v3 00/13] Clavis LSM

2025-02-27 Thread Paul Moore
On Thu, Feb 27, 2025 at 3:41 PM Mimi Zohar wrote: > On Mon, 2025-01-06 at 17:15 +, Eric Snowberg wrote: > > > On Jan 5, 2025, at 8:40 PM, Paul Moore wrote: > > > On Fri, Jan 3, 2025 at 11:48 PM Paul Moore wrote: > > > > > > > > Regardless, back to Clavis ... reading quickly through the cover

Re: [RFC PATCH v3 00/13] Clavis LSM

2025-02-27 Thread Mimi Zohar
On Mon, 2025-01-06 at 17:15 +, Eric Snowberg wrote: > > > On Jan 5, 2025, at 8:40 PM, Paul Moore wrote: > > > > On Fri, Jan 3, 2025 at 11:48 PM Paul Moore wrote: > > > > > > Regardless, back to Clavis ... reading quickly through the cover > > > letter again, I do somewhat wonder if this is

Re: [RFC PATCH v3 00/13] Clavis LSM

2025-01-03 Thread Paul Moore
On Fri, Jan 3, 2025 at 6:14 PM Eric Snowberg wrote: > > On Dec 23, 2024, at 5:09 AM, Mimi Zohar wrote: ... > > My main concern is not with Clavis per-se, but that the LSM > > infrastructure allows configuring all the LSMs, but enabling at build time > > and > > modifying at runtime a subset of

Re: [RFC PATCH v3 00/13] Clavis LSM

2025-01-03 Thread Eric Snowberg
Hi Mimi, > On Dec 23, 2024, at 5:09 AM, Mimi Zohar wrote: > > On Thu, 2024-10-17 at 09:55 -0600, Eric Snowberg wrote: >> Motivation: >> >> Each end-user has their own security threat model. What is important to one >> end-user may not be important to another. There is not a right or wrong >> t

Re: [RFC PATCH v3 00/13] Clavis LSM

2024-12-23 Thread Mimi Zohar
On Thu, 2024-10-17 at 09:55 -0600, Eric Snowberg wrote: > Motivation: > > Each end-user has their own security threat model. What is important to one > end-user may not be important to another. There is not a right or wrong threat > model. > > A common request made when adding new kernel changes

[RFC PATCH v3 00/13] Clavis LSM

2024-10-17 Thread Eric Snowberg
Motivation: Each end-user has their own security threat model. What is important to one end-user may not be important to another. There is not a right or wrong threat model. A common request made when adding new kernel changes that could impact the threat model around system kernel keys is to add