Re: LSM of Dazuko on kernel 2.6.32

errik <[email protected]> Mon, 21 Feb 2011 20:08:19 +0800
Newsgroups gmane.linux.dazuko.devel
Message-ID <[email protected]>
--===============0748898201==
Content-Type: multipart/alternative; boundary=000e0cd52ca034ef0c049cc9b8ee

--000e0cd52ca034ef0c049cc9b8ee
Content-Type: text/plain; charset=ISO-8859-1

Hi All,
    I have found a way to get the event type. I use file_permission to
replace inode_permission for the security hook point and use FMODE_EXEC &
file->f_flags to get the event type.
    When a sys_execve is called, the open_exec will return a struct file *
with file->f_flags set to FMODE_EXEC.

Thanks,
Errik
2011/2/18 errik <[email protected]>

> Hi John,
>     These days I am trying to find a way to do execve hook on 2.6.32
> kernel.
>     I  have tried dazukofs, it works with risk because we can't stop it
> after we mount a directory as dazukofs. The only way is to reboot the OS. If
> I mount watching directories to dazukofs, it has some potential impact to my
> server.
>     Also I tried redirfs, it only supports open and close hook not support
> execve hook.
>     At the end I tried to port Dazuko (LSM way) to kernel 2.6.32. The
> execve hook works fine with dazuko-LSM. But after I modify all the security
> APIs for 2.6.32, I found the kernel API  register_security is not exported
> event there is no kernel API unregister_security.
>
>     So I hope I can get some suggestions from you:
>     1. Is it possibile that I continue to use LSM on kernel 2.6.32? How can
> I do this? It seems kernel developers want to remove LSM from future kernel.
>
>      2. Can Dazuko catch execve events with RedirFS on kernel 2.6.32?
>
>      Looking forward to your suggestions.
>
> Thanks a lot,
> Errik
>
>
>
>
>

--000e0cd52ca034ef0c049cc9b8ee
Content-Type: text/html; charset=ISO-8859-1
Content-Transfer-Encoding: quoted-printable

<div>Hi All,</div>
<div>=A0=A0=A0 I have found a way to get the event type. I use file_permiss=
ion to replace inode_permission for the security hook point=A0and use FMODE=
_EXEC &amp; file-&gt;f_flags to get the event type. </div>
<div>=A0=A0=A0 When a sys_execve is called, the open_exec will return a str=
uct file * with file-&gt;f_flags set to FMODE_EXEC.</div>
<div>=A0=A0=A0 </div>
<div>Thanks,</div>
<div>Errik</div>
<div>2011/2/18 errik <span dir=3D"ltr">&lt;<a href=3D"mailto:waitingfor2009=
[email protected]">[email protected]</a>&gt;</span><br></div>
<div class=3D"gmail_quote">
<blockquote style=3D"BORDER-LEFT: #ccc 1px solid; MARGIN: 0px 0px 0px 0.8ex=
; PADDING-LEFT: 1ex" class=3D"gmail_quote">
<div>Hi John,</div>
<div>=A0=A0=A0 These days I am trying to find a way to do execve hook on 2.=
6.32 kernel. </div>
<div>=A0=A0=A0 I=A0 have tried dazukofs, it works with risk because we can&=
#39;t stop it after we mount a directory as dazukofs. The only way is to re=
boot the OS. If I mount watching directories to dazukofs, it has some poten=
tial impact to my server.</div>

<div>=A0=A0=A0 Also I tried redirfs, it only supports open and close hook n=
ot support execve hook.</div>
<div>=A0=A0=A0 At the end=A0I tried to port Dazuko (LSM way) to kernel 2.6.=
32. The execve hook works fine with dazuko-LSM. But after I modify all the =
security APIs for 2.6.32, I found the kernel API=A0 register_security is no=
t exported event there is no kernel API unregister_security. </div>

<div>=A0=A0 </div>
<div>=A0=A0=A0 So I hope I can get some suggestions from you:</div>
<div>=A0=A0=A0 1. Is it possibile that I continue to use LSM on kernel 2.6.=
32? How can I do this? It seems kernel developers want to remove LSM from f=
uture kernel.</div>
<div>=A0=A0=A0 </div>
<div>=A0=A0=A0=A0 2. Can Dazuko catch execve events with RedirFS on kernel =
2.6.32?</div>
<div>=A0</div>
<div>=A0=A0=A0=A0 Looking forward to your suggestions.</div>
<div>=A0</div>
<div>Thanks a lot,</div>
<div>Errik</div><font color=3D"#888888">
<div>=A0</div>
<div>=A0</div>
<div>=A0</div>
<div>=A0=A0=A0 </div></font></blockquote></div><br>

--000e0cd52ca034ef0c049cc9b8ee--


--===============0748898201==
Content-Type: text/plain; charset="us-ascii"
MIME-Version: 1.0
Content-Transfer-Encoding: 7bit
Content-Disposition: inline

_______________________________________________
Dazuko-devel mailing list
[email protected]
http://lists.nongnu.org/mailman/listinfo/dazuko-devel

--===============0748898201==--