Date: Sat, 8 Jul 2006 11:16:00 +0100 (BST) From: Robert Watson <rwatson@FreeBSD.org> To: trustedbsd-discuss@TrustedBSD.org Cc: freebsd-security@FreeBSD.org Subject: Poll for users: mac_partition and mac_ifoff policies Message-ID: <20060708111221.M94284@fledge.watson.org>
next in thread | raw e-mail | index | archive | help
Dear all, I'm currently in the process of reviewing the use of the MAC Framework in FreeBSD, following meetings at the developer summit about proposed simplifications and enhancements. One of the on-going concerns I have had is that several of the policies we ship are reference implementation policies, rather than reference user policies: mac_ifoff - Interface silencing mac_partition - Process space partitions mac_stub - Stub MAC policy entry points mac_test - Invariants testing While mac_stub and mac_test are both extremely useful for devleopers as shipped, it's not clear to me that mac_ifoff and mac_partition offer significantly similar value, and as they are reference policies rather than production policies, my leaning is to provide them as downloads on the TrustedBSD web site and via p4, but to not ship them with FreeBSD 7.0. So this e-mail is to poll to see if anyone is currently using the mac_ifoff and mac_partition policies in production, and would object on those grounds to shipping them separately from the base OS. Robert N M Watson Computer Laboratory University of Cambridge
Want to link to this message? Use this URL: <https://mail-archive.FreeBSD.org/cgi/mid.cgi?20060708111221.M94284>