Re: E + MinorFs + AppArmor: adding Tahoe to the stack ?

"Karp, Alan H" <[email protected]>
Newsgroups gmane.comp.lang.e.general
Message-ID <A0BE9926384D0940BBAD4B60190CB29A6B2F05F044@GVW0433EXB.americas.hpqcorp.net>
Matej Kosik wrote:
> 
> I do not understand the argument that AppArmor is indispensable (even if
> some process has to access files on the filesystem or interact with
> other processes). Is there a security policy which cannot be enforced in
> ocap-language (over untrusted modules written in this language)?
> Obviously (for me) not, but I guess you do not concur.
>
AppArmor will protect you if there is an exploitable flaw in the ocap program.

________________________
Alan Karp
Principal Scientist
Virus Safe Computing Initiative
Hewlett-Packard Laboratories
1501 Page Mill Road
Palo Alto, CA 94304
(650) 857-3967, fax (650) 857-7029
http://www.hpl.hp.com/personal/Alan_Karp
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.