Poll for users: mac_partition and mac_ifoff policies
Vlad GALU
vladgalu at gmail.com
Sat Jul 8 11:55:29 UTC 2006
On 7/8/06, Robert Watson <rwatson at freebsd.org> wrote:
>
> Dear all,
>
> I'm currently in the process of reviewing the use of the MAC Framework in
> FreeBSD, following meetings at the developer summit about proposed
> simplifications and enhancements. One of the on-going concerns I have had is
> that several of the policies we ship are reference implementation policies,
> rather than reference user policies:
>
> mac_ifoff - Interface silencing
> mac_partition - Process space partitions
> mac_stub - Stub MAC policy entry points
> mac_test - Invariants testing
>
> While mac_stub and mac_test are both extremely useful for devleopers as
> shipped, it's not clear to me that mac_ifoff and mac_partition offer
> significantly similar value, and as they are reference policies rather than
> production policies, my leaning is to provide them as downloads on the
> TrustedBSD web site and via p4, but to not ship them with FreeBSD 7.0. So
> this e-mail is to poll to see if anyone is currently using the mac_ifoff and
> mac_partition policies in production, and would object on those grounds to
> shipping them separately from the base OS.
I use mac_partition in production. However, I wouldn't mind having
it as a separate module as long as it doesn't become cumbersome to the
update (buildworld, installworld) process. In other words, I'd like
having it in sync with whatever OS branch I'm using.
>
> Robert N M Watson
> Computer Laboratory
> University of Cambridge
> _______________________________________________
> freebsd-security at freebsd.org mailing list
> http://lists.freebsd.org/mailman/listinfo/freebsd-security
> To unsubscribe, send any mail to "freebsd-security-unsubscribe at freebsd.org"
>
--
If it's there, and you can see it, it's real.
If it's not there, and you can see it, it's virtual.
If it's there, and you can't see it, it's transparent.
If it's not there, and you can't see it, you erased it.
More information about the trustedbsd-discuss
mailing list