TOMOYO Linuxã«å¦ã¶èª¬å¾è¡
æ¨æ¥ãTOMOYO Linuxã¡ã¤ã³ã©ã¤ã³åè¨å¿µåååå¼·ä¼ï¼ã«ã¼ãã«èªæ¸ä¼ãã»ãã¥ã¢OSã¦ã¼ã¶ä¼ãã¾ã£ã¡ã445ï¼ã«è¡ã£ã¦ãã¦ãå°å´ãããå¿åæ²ç¤ºæ¿ã§ã¬ãã§ã¬ãã¥ã¼ãã¦ããã話ãèããã®ã§ãæ©ééå»ãã°ãèªãã§ã¿ããhttp://tomoyo.sourceforge.jp/2ch/thread-2.txt
ï¼è¿½è¨ï¼2009/7/4 21:03 ãªããå¾åé¨åãã¢ã¹ãã¼ã¢ã¼ãã®å¾ãåãã¦ãã¾ã£ãã®ã§ãååé¨åãè¥å¹²ã«ãããã¦ï¼ç¥ï¼ã®é¨åããã®ï¼ã追å ãã¾ãããï¼
LKML (Linux Kernel Mailing List)ã¨ããã®ã¯Linuxã«ã¼ãã«ã®æè¡çãªãã¨ãè°è«ãããã£ã¨ã権å¨ï¼ï¼ï¼ããã¡ã¼ãªã³ã°ãªã¹ãã§ãããã§è°è«ããåæããããã®ãLinuxã®æ¬ä½ã«åãè¾¼ã¾ãããã¨ã«ãªãããã®Linuxã®æ¬å®¶æ¬å
ã®æ¬ä½ï¼ãã©ããªï¼ã®ãã¨ãã¡ã¤ã³ã©ã¤ã³ã¨å¼ã¶ãLinuxãåµã£ãLinusããã«ã¡ãªãã§Linus' treeã¨ããã¢ããã¹ããªã¼ã ã«ã¼ãã«ã¨ãå¼ã¶å ´åãããã
ãã®ã¡ã¤ã³ã©ã¤ã³ã«æ°æ©è½ãå ¥ããã®ã¯ç°¡åã§ã¯ãªããå¼·è ã®éçºè ãç´å¾ããæè¡çã¡ãªããããããããã説æããå¿ è¦ãããããã®æ¹æ³è«ã¨ããã®ãããããã¯å¦æ ¡ã§ãæãã£ã¦ããªãããè¨ç·´ããæ©ä¼ããã¾ããªãã®ã§LKMLã§ã®è°è«ãé¡æã«èª¬å¾è¡ã¨ãã観ç¹ã§å¦ãã§ã¿ããã
2ãã£ã³ãã«ã®ãã°ãåæ§æããªãããé©å®è§£èª¬ãªã©ãå ããã
æ¬å®¶LKMLã®éå»ãã°ã¯ä¸è¨ã«ããã®ã§ãé©å®åèã«ãã¦ã»ãããä¸è¨[1/10]ã¨ããã表è¨ã¯10åã®ãããã®ãã¡ã®ï¼åç®ã®ãããã«ã¤ãã¦ã®ã³ã¡ã³ãã示ãã
http://marc.info/?w=2&r=1&s=tomoyo+mmotm+2008-12-30-16-05&q=t
683 ï¼login:Penguinï¼2009/01/09(é) 22:36:28 ID:hv8sw/Ot TOMOYOãã¬ãã¥ã¼ãã¦ã¿ã LKMLã«æ稿ãã¦ããããã ããªã®ã§ãå ã«ãã¡ãã«æ¸ã [1/10] ã¾ããin_execveã¯ãã£ã±ã説å¾åããªããCREDã®ããã§åºæ¥ãªãã¨æ¸ãã¦ãããã ãããªãCREDç´ãã°åºæ¥ãããããã¨ãã話ã«ãªããªãã®ãï¼ã¨ããçåãããã å¥ã®å®è£ ãä¸åº¦ã¤ãã£ã¦ãSergeã«ãã£ã±åã®å®è£ ã®æ¹ããããã¼ãã£ã¦è¨ãããæ¹ãããã ã§ãªãã¨ããªã¬ã®ã¬ãã¥ã¼ãç¡è¦ããã®ãï¼ãªãNackã ã¼ã£ã¦è©±ã®æµãã«ãªããããªãã
LKMLã«æ稿ãã¦ããããã¨ããã®ã¯ãã¬ãã¥ã¢ã¼ã¨ãã¦å¿æ´ãããã®ã ãã©ãå³ããã³ã¡ã³ãããã£ã±ãããã®ã§ãããã§æ¥æ¬èªã§ååããã§ããLKMLã«è¡ããã¨ããããããæã®ããã£ãææ¡ã§ããã
Nackã¨ã¯ãå¦å®ã®æå³ãææ¡ããªã¸ã§ã¯ããããã¨ã
以ä¸2~10ã®ãããã«ã¤ãã¦ã®ã³ã¡ã³ããç¶ãã
684 ï¼login:Penguinï¼2009/01/09(é) 22:37:08 ID:hv8sw/Ot [2/10] Singly Listããã¡ãã£ã¨èª¬å¾ã§ãã¦ãªããããªã®ã§æ¨ã¦ãæ¹åã§ã¤ããç´ãã æ¹ããããã¨ããããããã ã³ã¢ãã¼ã¹ã¯ä»ã®ãããã®ã¤ãã§ã¿ãããªæ稿㮠ãããããå ¥ããªãã¨æãã Linusã以åããã¡ã ã¨è¨ã£ã¦ããããã¨ãè¨ã ãã¦ããããã ãã 685 ï¼login:Penguinï¼2009/01/09(é) 22:42:49 ID:hv8sw/Ot [3/10] d_realpath()ã¯patch descriptionããããªããpatch descriptionã¯ä½æ ãã ãå¿ è¦ãªã®ãã¨ã ãã®åé¡ã®ãã¤ã³ããã©ãã ã¨èãã¦ããã®ãã¨ãã話ã¨ã ã©ããã£ã¦è§£æ±ºãã¦ããã®ãã ã®ï¼ç¹ãå¿ è¦ã ããå®è£ ã®èª¬æãããªãã ã¾ããpathname based access control difficult ã®ä¸è¡ã ã㧠dcache.c ãã ãã®ã¯ããªãç¡ççã é£ããã ãã§ãå¯è½ãªãã ã£ããTOMOYOå´ã§ããããå ±éã«ã¼ãã³é¨åããããªã㨠åã«èª°ããããªã㧠d_path() ï¼ ã¦ã¼ã¶ã©ã³ãã§å å·¥ã§åºæ¥ãªãã®ï¼ã¨ãèãã¦ã ããããã¨ã»ãã¥ãªãã£ã¬ãã«ãè½ã¡ãã¨ã ãªããã¨ãçãã¦ãããã¼ãããªè¨æ¶ããããã©ã ãããpatch descriptionã«åæ ãã¦ããªãã ã¤ã¾ããæ°ãã人ãReviewãããã³ã«ãNackãå¢ããæ§é realpath()ã¯æªãååãd_path()ãfake ã§ãããã¨ãé£æ³ããããã©ã ããã§ã¯ãªããããã«TOMOYOã« é½åã®ããå½¢å¼ã®ãã®ãrealã¨å¼ã¶ã®ã¯ç¡çãããã ä»ã®ã¢ããªã§ã使ãããã¨ã説æããªãã¨ãreal ãããªãã§ããã ãã¡ãããçè«ä¸å¯è½ã£ã¦ãã¨ãããªãã¦ãå®éã« d_realpath()ã¤ãã£ã¦ ä»ã®ãµãã·ã¹ãã ããããªã«è¡æ°æ¸ã£ãã£ã¦ããããæ¸ãå¿ è¦ããã chrootã¨bind mountæã®ãµãã¾ãã¯ãã£ã¨ç´°ããæ¸ããªãã¨ãã¡ã ãããããããrootããä¸ããã©ããããªããã ããã ãã£ã¬ã¯ããªæã«/ãä»å ããã®ã¯ãTOMOYOå´ã§åºæ¥ãã¯ãã ããlinuxã®ãã¹ã® ã«ã¼ã«ã§ã¯ãªãTOMOYOã«ã¼ã«ãªã®ã§ã å ±éã«ã¼ãã³ã«ãããã¹ãã§ã¯ãªãã /proc/PID ã/proc/self ã«å¤æãã¦ãã®ãåããçæª 686 ï¼login:Penguinï¼2009/01/09(é) 22:49:07 ID:hv8sw/Ot [4/10] crazy ãªãã¡ã¤ã«åã«å¯¾ãã¦ã¨ã³ã³ã¼ããæ½ããªãã¨ã©ããã¦safeã§ãªããªãã®ã 説æããã¦ããªãã ã«ã¼ãã«å ã«ãã¼ãµã¼ãå ¥ãããã¨ã¯Linusããããã£ã¦ãããã¨ããã£ã¦ã ã¿ããªæ°ã«ããã®ã§ ãã£ã¨è©³ãã説æããæ¹ãããã åã®ææ³ã§ã¯ãããã«ããã°ãè¦ã«ãããªãã ãã ã£ããããããªå¦çå ¥ãããªã ã¨ããã®ãå ±éèªèã ã¨æã ãã°ã¯äººéãã¿ããã®ãªãã ãããè¦ãç´åã«å å·¥ããã°ããããããã¨ããçåãããã 687 ï¼login:Penguinï¼2009/01/09(é) 22:55:16 ID:hv8sw/Ot [5/10] å ¨è¬çã«ããã¼ãµã¼ãå ¥ãããªæ¹éã«åãã¦ããã®ã§å³ãããã Ingo ãftraceé¢ä¿ã§ãã¡ã¤ã«åãæ£è¦è¡¨ç¾ã§æå®ã§ããããã«ãããã ã£ã¦ä»¥åãã£ã¦ããããã ãã£ã¡ã«ååãã¦ãæ±ç¨çãªæ£è¦è¡¨ç¾ãã¹æå®é¢æ°ç¾¤ã linux/lib 以ä¸ã«ä½ã£ã¦ ãã£ã¡ã使ãããã«ä½ãããããã©ãããªï¼ ãã¨ã + case '$': /* "\$" */ + case '+': /* "\+" */ + case '?': /* "\?" */ + case '*': /* "\*" */ + case '@': /* "\@" */ + case 'x': /* "\x" */ + case 'X': /* "\X" */ + case 'a': /* "\a" */ + case 'A': /* "\A" */ + case '-': /* "\-" */ ãã®ã³ã¡ã³ãã¯ã²ã©ãããããªãã®èª¬æã«ããªã£ã¦ãªãã 688 ï¼login:Penguinï¼2009/01/09(é) 22:57:09 ID:hv8sw/Ot [6/10] TOMOYOã®ãã¡ã¤ã«ã ãã®å¤æ´ã ãããã¼ãµã¼ããªãããã誰ãæå¥ãè¨ããªãããã ã§ãpatch descriptionãï¼è¡ãªã®ã¯ã¡ãã£ã¨ã²ã©ã 689 ï¼login:Penguinï¼2009/01/09(é) 22:59:52 ID:hv8sw/Ot [7/10] ããã6/10ã¨åãã§ãå®å ¨ã«TOMOYOã«éãã話ãªã®ã§æå¥ã¯ã¤ããªãã¨æãã ãã ããããåããpatch descriptionãå¼±ãã TOMOYOã®ãã¡ã¤ã³é·ç§»ã«ã¼ã«ãªãã誰ãç¥ããªãã®ã ããä¾ã交ãã¤ã¤ä¸å¯§ã« 説æããªãã¨ã誰ã«ãã¬ãã¥ã¼ã§ããªãã®ã§ã¯ãªããã ã¬ãã¥ã¼ããã¦ãªãã¦ãããã¼ã¸ãããããªæ°ãããã®ã§ãç¡è¦ãã¦ããã£ã¦ããããã 690 ï¼login:Penguinï¼2009/01/09(é) 23:07:02 ID:hv8sw/Ot [8/10] RFCãªãã¨ãããããã¼ã¸ãããããããã§è°è«ã¨ã質åãæ¸ãã¦ãã£ã¦ãã ç¸æãå°ãã¨æãã ãã¨ãsecurity_task_free()ã¯Credãªãã¦ãäºå®ä¸ç¡æå³ã ã£ãã¯ãã task struct ã£ã¦RCUã¤ãã£ã¦ã ã¹ã¬ããæ»ãã ã¨ãã¨ã¯éãã¿ã¤ãã³ã°ã§æ§é ä½ç ´æ£ãã¦ãããã ãã¨ãã¨ä½¿ãéãªãã¦ç¡ãã£ãã ï¼ã¾ã¡ãã£ã¦ãï¼ï¼ tomoyo_domain_info ã«u32 ã追å ããæ¹å¼ã§ã¯ä½ãå°ãããå ¨ç¶æ¸ãã¦ãªãã®ã§ è¿äºã®ãããããªãã¨ããã®ãææ³ã ã»TOMOYOã®Tã¯taskã®Tãªãã âï¼ ã ããä½ï¼ ã»TOMOYOã«ã¨ã£ã¦nightmareãªãã âï¼çµå±çç±ããã¦ãªããããããã£ã¦ãã ã®ææ³ã ãã ã£ã¦è¦ããã¨æã 691 ï¼login:Penguinï¼2009/01/09(é) 23:07:34 ID:hv8sw/Ot [9/10] [10/10] ã¯No problemã¨æãã¾ãã
ãµã¼ãã²ã¨ã¤ã²ã¨ã¤ã®ãããã«ã¤ãã¦è©³ç´°ã«ã¬ãã¥ã¼ã³ã¡ã³ããæ¸ãã¦ãããããããªãLinuxKernelã³ãã¥ããã£ã®ãä½æ³ã§è¨ãã°ã¬ãã¥ã¼ã³ã¡ã³ãã¯LKMLã§ããã®ãçãªã®ã ãã©ãããããï¼chã§ãã£ãã®ã¯ãLKMLã§ããã¨ã¬ãã¥ã¢ã¼ãå¦å®çãªãã¨ãããããè¨ã£ã¦ããããã«åãåãããã®ãå«ã ããã ããã ã建è¨çãªè°è«ããããã£ãããã ãè±èªã ã¨èªåã®æ°æã¡ï¼å¿æ´ãã¦ãããã ãï¼ãä¼ãããªãã®ã§æ¥æ¬èªã§ããã¨ããªãã»ã©ã
@ITã®å¤§äººæ°é£è¼Linux Kernel Watch ã12月版 カーネルゆく年くる年、2009年に来る機能はどれだ?ã
ã§å°å´ããã¯ãããã ãçè
ã®ããã«ãµãã·ã¹ãã ã«é¢ä¿ãªãReviewed-byãæä¸ãã¾ãã£ã¦ããé£ä¸ããããã¨ãTOMOYOã¯å¤§ãéãã¦ã¡ãã£ã¨ã¬ãã¥ã¼ãããã©ãã®ãäºå®ã§ãããã¨è¨ãã¦ããã
692 ï¼login:Penguin âXkB4aFXBWg ï¼2009/01/09(é) 23:23:48 ID:8u0X+gul >>683 ã¬ãã¥ã¼ãããã¨ããããã¾ãããLKMLã§ã¯ãæ稿ããã¨ãéãããã£ã人ãã æè¦ãè¿°ã¹ãï¼ããã¦ç«ã¡å»ãï¼ã¨ããæãã§ãåç¬ã®æ¹ããå ¨ä½ãéãã¦ã®ã³ã¡ã³ãã ããã£ãã®ã¯ãããåãã¦ã§ããï¼kosakiãããæ¸ããã¦ããããã«ãå ¨ä½ãéãã¦ã¿ãã«ã¯ è¦æ¨¡ã大ãããªã£ã¦ãã¾ã£ãã¨ãããã¨ã§ãããã¾ãï¼ ææ¡ã§ã¯ãå®å ¨ãªããããç®æããã¨ããããã¯ããéãï¼ãã¼ã¸ãã¦ãããï¼ãã åªå ãã¦èãã¦ãã¾ãããæèè ã®æ¹ã®ãæè¦ã¯é²è¡ä¸ã®ããã¨ããä»å¾ã®ãããã®åèã« ãªãã¨æãã¾ããä»ã®æ¹ã§ããæè¦ããææ¡ãããã°æ¯éãèãããã ããã
692ã®æ¸ãè¾¼ã¿ã®ãkosakiãããæ¸ããã¦ããããã«ãå ¨ä½ãéãã¦ã¿ãã«ã¯è¦æ¨¡ã大ãããªã£ã¦ãã¾ã£ãã¨ãããã¨ã§ãããã¾ããã¯ä¸è¨Linux Kernel Watchã®è¨äºã®ãã¨ã ã¨æãã®ã ãã©ããªãããæ¬äººéè¨ã
693 ï¼login:Penguinï¼2009/01/09(é) 23:29:01 ID:hv8sw/Ot ãªããªãã§ãªã¤ã©ã kosaki ã£ã¦åãã£ãã®ãã ããã証æ ã¯ã©ãã«ãããã ãããããã¼ 2chãå¿åæ²ç¤ºæ¿ã¨ããã®ã¯ã¦ã½ã 㪠694 ï¼login:Penguin âXkB4aFXBWg ï¼2009/01/09(é) 23:32:52 ID:8u0X+gul ãã¯ãã»ã»ã»ã(=_=;
693ã¯ã¹ã«ã¼ããã°ããã®ã«ãèªãå¢ç©´ãæãã¨ã¯ãã®ãã¨ãªãã ãªãã¬ãã¥ã¢ã¼ãå°å´ããã ã¨ãããã¨ãèªããçºè¨ã
æ¥æ¬çºã®ãªã¼ãã³ã½ã¼ã¹ã®ããã¸ã§ã¯ãã§ã¯ããååå¿åï¼ãã³ãã«åï¼ã§éçºãããã¨ã¯ããã»ã©çãããã¨ã§ã¯ãªãããï¼chã§è¶
çé¢ç®ãªè°è«ãããããå±éããããã¨ã«ãªãã
697 ï¼login:Penguin âXkB4aFXBWg ï¼2009/01/10(å) 00:00:53 ID:86I9WRb8 >>684 >Singly Listããã¡ãã£ã¨èª¬å¾ã§ãã¦ãªããããªã®ã§æ¨ã¦ãæ¹åã§ã¤ããç´ããæ¹ããããã¨ããããããã >ã³ã¢ãã¼ã¹ã¯ä»ã®ãããã®ã¤ãã§ã¿ãããªæ稿ã®ãããããå ¥ããªãã¨æãã >Linusã以åããã¡ã ã¨è¨ã£ã¦ããããã¨ãè¨ããã¦ããããã ãã ããã§ãã³ã¢ãã¼ã¹ãã¨ã¯ãæ±ç¨ã®ã¨ããæå³ã§æ¸ãã¦ãã¾ããï¼ å®éã«ã¯ãlist1ã¯ã確ãã«çæ¹åã®ãªã¹ããã§ã¯ããã¾ããã åé¤ãªãï¼read lockä¸è¦)ã§ãå®è³ªçã«ã¯tomoyoå°ç¨ï¼åºæï¼ã§ãã ãªã®ã§æ¨æ¥Sergeã¸ã®ãªãã©ã¤ã§ã¯ã >Thus, I'd like to rename to "rlfl" (Read-Lock-Free List). ã¨è¿ä¿¡ãã¦ãã¾ãã 699 ï¼login:Penguinï¼2009/01/10(å) 04:04:54 ID:Dw+abJQq >>697 ãããã®æå°åã®è¦³ç¹ããããã¨ver1ã¯lock freeãæ¨ã¦ã¦ã æ¯åmutexãã¨ãä½ãã«ãã¦ããããã¡ããã®ï¼ï¼¿ éä¸ã§å¯ããããäºã ã£ã¦ã®ã¯spin_lock ãèããããåé¡ã«ãªãã®ã§ãããã»ã»
çæ¹åãªã¹ãã¨ããã®ã«TOMOYOã¯å¦ã«ãã ãã£ã¦ããããã ãã©ããã¼ãã¼ã¨ããã¯æ¨ã¦ã¦ãããã®ã§ã¯ãªããã¨ããããªãå®è£ ã®ç´°é¨ã«ãã ããã®ã¯æ¨ãè¦ã¦æ£®ãè¦ãã«ãªããã¡ã¨ãããã¨ãã
çç«ããã®ææ¶ã®ã¬ãã¥ã¼ã«å¯¾ããã³ã¡ã³ãè¿ããå§ã¾ãã
700 ï¼login:Penguinï¼2009/01/12(æ) 16:34:37 ID:SrCsF0ph >>676 çç«ã¯æ¨æã®å¤ãã風éªã§ãã»ã¨ãã©å¸å£ã®ä¸ã§ãã >>666 >TOMOYOã¯æ§è½ã ããããªãæ©è½ãè±å¯ãªã®ã§ããã¤ãè½ã¨ãã¦ãããããããªãï¼ ã¬ãã¥ã¼ãããã¨ããããã¾ãã ããã§ãæå°éã®æ©è½ãªãã§ããï¼æ³£ï¼ >>675 > ï¼ï¼ãã ãæ®éã®listã使ãããã«ãæ¸ãç´ããæ°ãããã æ¸ãç´ãã¾ããã prev ãã¤ã³ã¿ã¸ã®ã¢ã¯ã»ã¹ãçºçãããã read lock ãéæã« å°å ¥ããç¾½ç®ã«ãªãã¾ãã TOMOYO ã巨大ãªå²ã«ã·ã³ãã«ãªã®ã¯ã delete ããªããã¨ã§ read lock ã使ããªãã¨ããå²ãåãããã¦ããããã§ããï¼æè©®ãæ¶è²»ã¡ã¢ãªã¯ ï¼ã¡ã¬ãã¤ã以å ã§ããããï¼ > ï¼ï¼in_execveã«ã¤ãã¦ã¯ãå®ã¯ï¼æ¡æ¤è¨ãããã ãã©ããï¼ã¤ã®æ¡ã¯ã > ãããªã«Uglyãªã®ã§in_execveã®ã»ãããã¯ããã«ãã·ãªãã ã Sarge ã¯æ¢ã«ï¼æ¡ã¨ãç¥ã£ã¦ããã in_execve ã®æ¹ããã·ã ã¨è¿°ã¹ã¦ãã¾ãã David Howells ã®ã³ã¡ã³ããæ±ãã¨æ稿ãã¾ããããã¾ã æ¬äººããã®ã³ã¡ã³ã㯠ããã¾ãããæ¬äººããªã³ã©ã¤ã³ãªã®ã¯ç¢ºèªãã¿ã§ãã
ãã¦ãããããã®æ©è½ã«ã¤ãã¦è©³ç´°ãªè³ªçå¿çãè°è«ãå§ã¾ããã¬ãã¥ã¢ã¼å¯¾å®è£ è ï¼ä¸»ã«çç«ããï¼ãæä¸ã®ï¼ï¼700ã¨ããã®ã¯700çªã®è©±é¡ï¼700 ï¼login:Penguinï¼2009/01/12(æ) 16:34:37 id:SrCsF0phï¼ã«ã¤ãã¦è¿äºãæ¸ãã¦ããã¨ãããã¨ã§ããã
705 ï¼login:Penguinï¼2009/01/12(æ) 17:02:24 ID:fsX40d3O >>700 ï¼> ï¼ï¼ãã ãæ®éã®listã使ãããã«ãæ¸ãç´ããæ°ãããã ï¼æ¸ãç´ãã¾ããã prev ãã¤ã³ã¿ã¸ã®ã¢ã¯ã»ã¹ãçºçãããã read lock ãéæã« ï¼å°å ¥ããç¾½ç®ã«ãªãã¾ãã TOMOYO ã巨大ãªå²ã«ã·ã³ãã«ãªã®ã¯ã delete ããªããã¨ã§ ï¼read lock ã使ããªãã¨ããå²ãåãããã¦ããããã§ããï¼æè©®ãæ¶è²»ã¡ã¢ãªã¯ ï¼ï¼ã¡ã¬ãã¤ã以å ã§ããããï¼ ã¤ã¾ãããã®ã·ã³ãã«ãããã¼ã¸è°è«ãå°é£ãã価å¤ããããã©ãããã¨ãã天秤ã®åé¡ã¨ æã£ã¦ãã¾ãã éæã«å°å ¥ããã¨å ·ä½çã«ä½è¡å¢ããã®ãæ°å¤ã¯ãã£ã¦ã¾ããï¼ ãã£ã¨ããã¨ä»ã®ãµãã·ã¹ãã 人ã¯tomoyoãã£ã¬ã¯ããªä»¥ä¸ãmessyã§ãããã¾ãæ°ã« ããªããã© ã³ã¢ã³ã¼ãã«è¦ç¥ãã¬ã³ã¼ããå ¥ãã¨ãæ¶æ¥µçå対ããã¬ã¹ãã¤ãå§ãããã è°è«ãé¯ç¶ããã¡ã« æãã ãã¨ãã°ãæåã¯TOMOYOãã£ã¬ã¯ããªã«singly listã³ã¼ãããã¦ããã¦ã ããããã£ã¹ã¯ãªãã·ã§ã³ã« ä»ã«ä½¿ã人ãåºãæç¹ã§å ´æã移åãããäºå®ã ã¨ãæ¸ãã®ã¯ãã¡ï¼ ï¼> ï¼ï¼in_execveã«ã¤ãã¦ã¯ãå®ã¯ï¼æ¡æ¤è¨ãããã ãã©ããï¼ã¤ã®æ¡ã¯ã ï¼> ãããªã«Uglyãªã®ã§in_execveã®ã»ãããã¯ããã«ãã·ãªãã ã ï¼Sarge ã¯æ¢ã«ï¼æ¡ã¨ãç¥ã£ã¦ããã in_execve ã®æ¹ããã·ã ã¨è¿°ã¹ã¦ãã¾ãã ï¼David Howells ã®ã³ã¡ã³ããæ±ãã¨æ稿ãã¾ããããã¾ã æ¬äººããã®ã³ã¡ã³ã㯠ï¼ããã¾ãããæ¬äººããªã³ã©ã¤ã³ãªã®ã¯ç¢ºèªãã¿ã§ãã ããã§ç¬¬ä¸è ã ãããªã®ã¯ãªããªã®ï¼ è°è«ã®é²ãæ¹ã¨ãã¦æªæã«è¦ãããã ããã©ãã David Howells ã¯çµ¶å¯¾TOMOYOã«è¯ãæ¹åã«ã³ã¡ã³ããã¦ãããããäºåã«ãã´ã£ã¦ ããã®ï¼ ã§ããªããã°ããã£ããDavidã¯å¿ãã¦Sergeæ»ç¥ããã»ãããããªãï¼
ããããã£ã¹ã¯ãªãã·ã§ã³(patch description)ã¨ã¯æ稿ãããããã®èª¬æãè¨è¿°ããææ¸ãããã«ãã£ã¦ããããã®æå³ãç®çãªã©ãã¬ãã¥ã¼ãããã«ã¼ãã«ããã°ã©ããç解ãããå¾ã£ã¦ããã®æ¸ãæ¹ã¯é常ã«éè¦ã
ããã«ä¸åä¸çãç¶ãã
701 ï¼login:Penguinï¼2009/01/12(æ) 16:35:45 ID:SrCsF0ph >>680 > æ¨ã¦ãããé¨åãã©ãããç¥ããªããã©ãï¼ç¹ã«d_realpathã¨ãï¼ æ¨ã¦ããã¾ããã éå»ã®ææ¡ã§ã¯ security/tomoyo/ 以ä¸ã ãã®ä¿®æ£ã§æ¸ãããã«ãªã£ã¦ããã TOMOYO ã使ããªãã«ã¼ãã«ã®ããã«ã³ã¼ãã大ãããªããªãããã«é æ ®ãã¦ãã¾ããã ããããçç«ã®è¨æ¶ãæ£ãããã°ãããã®ãªã¹ãã¯å ±éé¨åã¨ãã¦ä½¿ãããã security/tomoyo/ 以ä¸ã«ç½®ãããã include/linux/ 以ä¸ã«ç½®ãæ¹ãè¯ãã®ã§ã¯ï¼ã ããã®å¦ç㯠d_path() ã¨åæ§ã ãã security/tomoyo/ 以ä¸ã«ç½®ãããã fs/dcache.c ã«å ¥ããæ¹ãè¯ãã®ã§ã¯ï¼ãã¨ã¢ããã¤ã¹ãããããã«å¾ã£ããä»åº¦ã¯ ãã³ã¢ã³ã¼ãã«æãå ãããªãã¨åçºãå°ãã£ã¦ããããã«æãã¦ãã¾ãã ã©ãã TOMOYO ãã使ããªãã§ããããããç½®ãå ´æãåé¡ãªã®ã§ããã° security/tomoyo/ 以ä¸ã«ç§»åãããã ãã®è©±ã§ãã >>683 > ãããªãCREDç´ãã°åºæ¥ãããããã¨ãã話ã«ãªããªãã®ãï¼ã¨ããçåãããã credentials ããã㯠TOMOYO ã out-of-tree ã®ç¶æ ã§æ¤è¨ããããã¼ã¸ããã¾ããã æ´»çºãªæ¤è¨ãè¡ããã¦ããã®ã¯è¦ã¦ãã¾ãããã TOMOYO ããã¼ã¸ãããåã« credentials ããã¼ã¸ããããã¨ã¯æ³å®ãã¦ããªãã£ãã®ã§ã credentials ç¡ãã® ç¶æ 㧠TOMOYO ã®éçºãç¶ãããã¾ããã credentials ããã¼ã¸ããã¦ãã¾ã£ãç¾å¨ã§ã TOMOYO 㯠out-of-tree ã§ããããã TOMOYO å´ãããä»ã¾ã§ã§ãã¦ãããã¨ãã§ããªããªã£ãããªã°ã¬ãã·ã§ã³ã ã ä½ã¨ããã¦ããããã¨è¦æ±ãããã¨ã¯ã§ãã¾ããã credentials ã«å½±é¿ãä¸ããªãç¯å²ã§ workaround ãæ¢ãã®ãç²¾ãã£ã±ãã§ãããã
ããã«å¯¾ããã³ã¡ã³ãè¿ãã
706 ï¼login:Penguinï¼2009/01/12(æ) 17:11:01 ID:fsX40d3O >>701 ï¼ç¥ï¼ ï¼ããã®å¦ç㯠d_path() ã¨åæ§ã ãã security/tomoyo/ 以ä¸ã«ç½®ãããã fs/dcache.c ã« ï¼å ¥ããæ¹ãè¯ãã®ã§ã¯ï¼ãã¨ã¢ããã¤ã¹ãããããã«å¾ã£ããä»åº¦ã¯ ï¼ãã³ã¢ã³ã¼ãã«æãå ãããªãã¨åçºãå°ãã£ã¦ããããã«æãã¦ãã¾ãã ï¼ã©ãã TOMOYO ãã使ããªãã§ããããããç½®ãå ´æãåé¡ãªã®ã§ããã° ï¼security/tomoyo/ 以ä¸ã«ç§»åãããã ãã®è©±ã§ãã ããã¯å ¸åçãªã³ã¡ã³ãã«ã¯å¾ã£ããè¡éãèªãã§ãªãã£ãã£ã¦ãã¨ãªãã ã¨æãã å ±éé¨ã¸ç§»åã£ã¦ã®ã¯ãããã«ãã¡ã¤ã«ã®å ´æã移åããã ããããªããå ±éé¨ã«ãµãããã ã³ã¼ãã¸å¤ãã¦ããã£ã¦äºãå½ç¶æ±ãããã¦ããã¨æãã ãããããåã« security/tomoyo/ ã«æ»ãã£ã¦ã®ã¯ãããã®ã¬ãã¥ã¼ã³ã¡ã³ããç¡è¦ããã®ãã åé¡ãåºãããªãã®ã§ãããããã¨ããã¿ã¤ãã³ã°ãåå³ããæ¹ãããã¨æãã ä¸çªããã®ã¯singly list ã¨ãããããæå¥ã¯æ¨ã¦ã¦ãRCU safe list ã¨ãã¦ãã¡ããã¨ããã«ãµãããã æä½ã«ã¼ãã³ãä¸éãå ¥ãã¦Linusã説å¾ãããã¨ã ã¬ãã¥ã¼ã¢ã¼ã®æå¾ å¤ã¯ããã ã¨æãã åãã¬ãã¥ã¼ã¯ã¼ã ã£ãããããã«tomoyoã«ç§»åãããã ããªãNackããã®ã§é¸æè¢ã¯ ã»æ®éã®listã使ã ã»TOMOYOã®å©ç¨æ¹æ³ã«éããªããã¡ããã¨ããRCU safe listãã¤ãã£ã¦linusãèª¬å¾ ã®ï¼æã¨æãããã¡ããåè ããeasy.
è¡éãèªãã§ããªãã
707 ï¼login:Penguinï¼2009/01/12(æ) 17:16:08 ID:fsX40d3O >>701 ï¼> ãããªãCREDç´ãã°åºæ¥ãããããã¨ãã話ã«ãªããªãã®ãï¼ã¨ããçåãããã ï¼credentials ããã㯠TOMOYO ã out-of-tree ã®ç¶æ ã§æ¤è¨ããããã¼ã¸ããã¾ããã ï¼æ´»çºãªæ¤è¨ãè¡ããã¦ããã®ã¯è¦ã¦ãã¾ãããã TOMOYO ããã¼ã¸ãããåã« ï¼credentials ããã¼ã¸ããããã¨ã¯æ³å®ãã¦ããªãã£ãã®ã§ã credentials ç¡ãã® ï¼ç¶æ 㧠TOMOYO ã®éçºãç¶ãããã¾ããã éå»ã®çµç·¯ã¯è·æ¥æåãã¦ããã¾ã(^^;; ï¼credentials ããã¼ã¸ããã¦ãã¾ã£ãç¾å¨ã§ã TOMOYO 㯠out-of-tree ã§ããããã ï¼TOMOYO å´ãããä»ã¾ã§ã§ãã¦ãããã¨ãã§ããªããªã£ãããªã°ã¬ãã·ã§ã³ã ã ï¼ä½ã¨ããã¦ããããã¨è¦æ±ãããã¨ã¯ã§ãã¾ããã credentials ã«å½±é¿ãä¸ããªãç¯å²ã§ ï¼workaround ãæ¢ãã®ãç²¾ãã£ã±ãã§ãããã ãªãï¼ ãªã°ã¬ãã·ã§ã³ã§ãªãã®ã¯ç¢ºãã ããã©ããæ¬å½ã«å¿ è¦ãªãTOMOYOã®ããã«ã CREDãããã£ã¦ãããã®ã§ãï¼ èª¬å¾ã§ããªããããªçç±ãªã®ï¼ ãã¡ãããCREDã®äººããè¦ãã¨ãTOMOYOã®ããã«å¤ãã¦ãããã¨è¨ããããæãã¨æãã®ã§ ã«ã¼ãã«å ¨ä½ã«ã¨ã£ã¦å©çãããã¨ç´å¾ãããã ãã®çè«æ¦è£ ã¯å¿ è¦ã¨æããã ç¹°ãè¿ããã©ãã³ã¢ã³ã¼ããããããã¨èªä½ã¯èª°ãå対ãã¦ãªãã¨æããã ã ãã ããããã£ã¹ã¯ãªãã·ã§ã³ã«TOMOYOã®é½åãæ¸ãã¦ããã¨ãã¿ããªTOMOYOã®äºãªãã ç¥ããªãããæ¶æ¥µçå対ãã話ãã¹ã¿ã¼ããã¦ãã¾ãã¨æãã
èªåã®é½åã ããæ¸ãã¦ããã¨å ±æãå¾ãããªãã¨ããã話ããããç©æ¥µçè³æãçãã®ã§ã¯ãªããæ¶æ¥µçå対ãçãããªãã»ã©ã
702ããç¶ãã¹ã¬ããã
702 ï¼login:Penguinï¼2009/01/12(æ) 16:36:55 ID:SrCsF0ph >>684 > Linusã以åããã¡ã ã¨è¨ã£ã¦ããããã¨ãè¨ããã¦ããããã ãã Linus ã以å No ã¨è¨ã£ãã¨ãã¦ããæ¢ã« 2.6.28 ã§ã¯ä½åãã® in-tree 㪠singly linked list ã®å©ç¨è ãåå¨ãã¦ãã¾ãããããã in-tree ã¨ãªããã¨ã ç®æãã¦ãã TOMOYO ã singly linked list ã使ã£ã¦ã¯ãããªãã¨è¨ãããã®ã¯ ä¸å ¬å¹³ã ã¨æãã¾ãã singly linked list ã API ã¨ã㦠include/linux/ 以ä¸ã«ç½®ããã¨ã«å¯¾ã㦠Linus ã No ã¨è¨ã£ã¦ããã®ãªãã°ã security/tomoyo/ 以ä¸ã«ç½®ããã¨ã«ãªãã§ãããã Linus ã singly linked list ãã®ãã®ã«å¯¾ãã¦ç¾å¨ã No ã§ããã¨ããããä½æ ä½åãã® in-tree 㪠singly linked list ã®å©ç¨è ãã«ã¼ãã« 2.6.28 ã« æ®ã£ã¦ããã®ã§ããããï¼ >>685 > realpath()ã¯æªãååãd_path()ãfake ã§ãããã¨ãé£æ³ããããã©ã ããããæè¦ã¯ããã¾ããã§ãããã©ã¤ãã©ãªé¢æ°ã¨ã㦠realpath(3) ã¨ãããã®ã ããã®ã§ã ã«ã¼ãã«çã® realpath(2) ã¨å½åãã¾ããã AppArmor 㯠d_namespace_path() ã¨ããååã 使ã£ã¦ããã®ã§ã TOMOYO ã§ã¯ d_ns_path() ãããã§ãããããï¼ï¼ /proc/self ã®ä¾å¤æ±ãã® åé¡ãããã®ã§ AppArmor ã¨è¡çªããååã¯é¿ãããã§ããï¼ > /proc/PID ã/proc/self ã«å¤æãã¦ãã®ãåããçæª ãã㯠d_realpath() å ã§ãªãã¨å®è£ ã§ãã¾ããã "proc/æ°å¤" ã¨ããæåå㨠ä¸è´ããã¨ãã¦ã ãæ°å¤é¨åãå¿ ãããã»ã¹ï¼©ï¼¤ã§ãããã¨ããä¿è¨¼ãç¡ãããã§ãã ã¾ãã procfs ã proc2 ã« ãã¦ã³ãããã¦ããã "proc2/æ°å¤" ã¨ããæåå㧠å¤å®ããªããã°ãããªããªãã¾ãã çãæªãã¨è¨ããããã¨ããæååã«å¤æå¾ã«æ¨æ¸¬ãã¦ç½®æããæ¹å¼ã¯ TOMOYO ã¨ãã¦ã¯ 容èªã§ãã¾ããã
708 ï¼login:Penguinï¼2009/01/12(æ) 17:24:23 ID:fsX40d3O >>702 ï¼> Linusã以åããã¡ã ã¨è¨ã£ã¦ããããã¨ãè¨ããã¦ããããã ãã ï¼Linus ã以å No ã¨è¨ã£ãã¨ãã¦ããæ¢ã« 2.6.28 ã§ã¯ä½åãã® in-tree 㪠ï¼singly linked list ã®å©ç¨è ãåå¨ãã¦ãã¾ãããããã in-tree ã¨ãªããã¨ã ï¼ç®æãã¦ãã TOMOYO ã singly linked list ã使ã£ã¦ã¯ãããªãã¨è¨ãããã®ã¯ ï¼ä¸å ¬å¹³ã ã¨æãã¾ãã ã¾ã£ããããã¯æãã¾ããã ä»ã¾ã§ãæ°ã ã®è°è«ã§prevã¡ã³ãã¼ã使ããªãã±ã¼ã¹ã§ããäºéãªã¹ãã§æ§è½å£åã ãªããããä¸å¿ è¦ã«ã«ã¼ãã«ã³ã¼ããè¨å¼µãããå¿ è¦ãªããããã¨ããã®ãçµè«ã ãªã®ã§ãä»ã¾ã§çµè«éãTOMOYOãäºéãªã¹ãã使ããã©prevã¡ã³ãã¯ä½¿ããªãç¶æ ã ç¶æãããªã誰ãããNackã¯é£ãã§ããªãã ï¼singly linked list ã API ã¨ã㦠include/linux/ 以ä¸ã«ç½®ããã¨ã«å¯¾ã㦠ï¼Linus ã No ã¨è¨ã£ã¦ããã®ãªãã°ã ããã¯è¨ã£ã¦ãªãã¨ããèªèã ãã¾ã¾ã§ãSingly linked listãä½ãã¡ãªããããã¡ããã¨èª¬æã§ãã人ãããªãã®ã§ã NOã ã£ãã¨ãã èªèã ãä¸å¿ è¦ãªãã³ã¼ã追å ã¯ããã ãã¨è¨ããã¦ããã ã§ããLinusãä¸åº¦slistã¯ãããªããã¨å¤æãããã¨ã§ããã¨ããµãã·ã¹ãã ã¡ã³ããã§ã¯ ã²ã£ããè¿ããªãã®ã§èªåã§Linusã説å¾ãã¦ããã¨ããããã®ãèªç¶ã®æµãã ãã¾ã®list1ã ã¨èª¬å¾ã¯ç¡çã ã¨ããããã©ãLinusã¯RCU好ãã£ããªãã ããã ãã£ã¡ãåé¢ã«åºãã°èª¬å¾ã§ããããããªãã®ï¼ 大äºãªã®ã¯TOMOYOã®ä¾¡å¤è¦³ãããªãã¦ãã³ãã¥ããã£ã®ä¾¡å¤è¦³ã§è°è«ã»èª¬å¾ãããã¨ã ã¨æãã
大äºãªã®ã¯TOMOYOã®ä¾¡å¤è¦³ãããªãã¦ãã³ãã¥ããã£ã®ä¾¡å¤è¦³ã§è°è«ã»èª¬å¾ãããã¨ã ã¨æãã
709 ï¼login:Penguinï¼2009/01/12(æ) 17:24:44 ID:fsX40d3O >>702 ï¼security/tomoyo/ 以ä¸ã«ç½®ããã¨ã«ãªãã§ãããã ããããããªãã§ããçç±ã¯ï¼ã¤ãï¼ã¤åã«æ¸ããã¨ããã ï¼Linus ã singly linked list ãã®ãã®ã«å¯¾ãã¦ç¾å¨ã No ã§ããã¨ããããä½æ ï¼ä½åãã® in-tree 㪠singly linked list ã®å©ç¨è ãã«ã¼ãã« 2.6.28 ã« ï¼æ®ã£ã¦ããã®ã§ããããï¼ ä¸ã§ãæ¸ãããã©ãä¸çªã®åé¡ã¯ä»ã®ããããã£ã¹ã¯ãªãã·ã§ã³ã«æ¸ãã¦ãã ãTOMOYOã¯prevã¡ã³ãã¯ä½¿ããªããã£ã¦ã®ã¯ã¾ã£ããçç±ã«ãªã£ã¦ãªãã¨ãããã¨ã ä»ã®ä½åã®ãµãã·ã¹ãã ãprev使ã£ã¦ãªããã©äºåãªã¹ãã§ãã£ã¦ãç¶æ³ãããããã ãã¡ãªããããªããã°ã³ã¼ã追å ããªããã¨ãã価å¤è¦³ãåæã«çè«æ¦è£ ãã¦èª¬å¾ããã®ã ããã¨æãã 710 ï¼login:Penguinï¼2009/01/12(æ) 17:33:49 ID:fsX40d3O >>702 ï¼> realpath()ã¯æªãååãd_path()ãfake ã§ãããã¨ãé£æ³ããããã©ã ï¼ããããæè¦ã¯ããã¾ããã§ãããã©ã¤ãã©ãªé¢æ°ã¨ã㦠realpath(3) ã¨ãããã®ãããã®ã§ã ï¼ã«ã¼ãã«çã® realpath(2) ã¨å½åãã¾ããã AppArmor 㯠d_namespace_path() ã¨ããååã ï¼ä½¿ã£ã¦ããã®ã§ã TOMOYO ã§ã¯ d_ns_path() ãããã§ãããããï¼ï¼ /proc/self ã®ä¾å¤æ±ãã® ï¼åé¡ãããã®ã§ AppArmor ã¨è¡çªããååã¯é¿ãããã§ããï¼ ããããªãã»ã©ããã£ã¡ãã ãããããsimilar to realpath(3)ãã¨ãæ¸ãã¦ãprintk ã¨ã strcpy ã¨ãã¨åããã libc ã«ããããåãããããååãç®æãã¦ãããã ãããã¨ãããããã£ã¹ã¯ãªãã·ã§ã³ã« ããã¹ãã¨æãã ãã¨ã絶対ãã¹ã¯ãã¼ã ã¹ãã¼ã¹ä¾åãªãã ãã©ããããç¡è¦ãã¦ããã®ãçæªã¨æãã å¼æ°ã§åãåã£ãtaskã®ãã¼ã ã¹ãã¼ã¹ã§resolvãããã©ãNULLã ã£ãã ã°ãã¼ãã«ãã¼ã ã¹ãã¼ã¹ãã¨ãflagå¼æ°ã追å ããã¨ããããã»ããããæ°ãããã ï¼fsç³»ãããããªãã®ã§ãå¤ãã¦ããããï¼ 711 ï¼login:Penguinï¼2009/01/12(æ) 17:37:18 ID:fsX40d3O >>702 ï¼> /proc/PID ã/proc/self ã«å¤æãã¦ãã®ãåããçæª ï¼ãã㯠d_realpath() å ã§ãªãã¨å®è£ ã§ãã¾ããã "proc/æ°å¤" ã¨ããæååã¨ä¸è´ããã¨ãã¦ã ï¼ãæ°å¤é¨åãå¿ ãããã»ã¹ï¼©ï¼¤ã§ãããã¨ããä¿è¨¼ãç¡ãããã§ããã¾ãã procfs ã proc2 ã« ï¼ãã¦ã³ãããã¦ããã "proc2/æ°å¤" ã¨ããæååã§å¤å®ããªããã°ãããªããªãã¾ãã ï¼çãæªãã¨è¨ããããã¨ããæååã«å¤æå¾ã«æ¨æ¸¬ãã¦ç½®æããæ¹å¼ã¯ TOMOYO ã¨ãã¦ã¯ ï¼å®¹èªã§ãã¾ããã ãã®çå±ã¯çµ¶å¯¾ãã¡ããTOMOYOã®çå±ã«ãªã£ã¦ãããã«ã¼ãã«å ¨ä½ããã¿ã¦ãä»ã®ä»æ§ã æã¾ãããã ã¼ã¼ã£ã¦è¨ããã®ãå¿ é ã å°ãªãã¨ããflags å¼æ°ã追å ãã¦ãTOMOYOä»æ§ã¯ãããflagãONã®ã¨ãã ãåãã ã¨ããããããã¯åºæ¥ããã«æãã ä»ã®ä»æ§ã§Ackãã人ã¯ããªãã¨æããã©ãè¦ã¦ãTOMOYO以å¤ã«ä½¿ããªãé¢æ°ã«ãªã£ã¦ããã®ã
TOMOYOã®é½åãæ¼ãã¦ããã¨ããã®ããã¡ãªçç±ã¨ã®ææãç¸æã«åã£ã¦ãã¨ããã¡ãªãããããããXXXã¨ããã¨ãã表ç¾ã«ããªãã¨åãå ¥ããããªããã«ã¼ãã«ã«ã¨ã£ã¦ä½ãããããã®ããã©ã¼ããã¹ããã¨ãã説æã§ãªãã¨ã ãã ã
703ã®ã¹ã¬ããã
703 ï¼login:Penguinï¼2009/01/12(æ) 16:38:11 ID:SrCsF0ph >>686 > crazy ãªãã¡ã¤ã«åã«å¯¾ãã¦ã¨ã³ã³ã¼ããæ½ããªãã¨ã©ããã¦safeã§ãªããªãã®ã説æããã¦ããªãã TOMOYO ã®æ ¹åºããªãèå¥åã¨ãã¦ããã¡ã¤ã³åãã¨ãããã®ãããã¾ãããã®ãã¡ã¤ã³å㯠起ç¹ã¨ãªãï¼kernelï¼ã¨ããæååã«ããã®ãã¡ã¤ã³ã«å°éããã¾ã§ã«å®è¡ããã ããã°ã©ã 㮠絶対ãã¹åãé£çµï¼åºåãã¨ã㦠0x20 ã使ç¨ï¼ãããã®ã¨ãã¦å®ç¾©ããã¾ãã ãããã Linux ã§ã¯ã ãã¹åã«ã¯ 0x20 ãå«ãã¦å ¨ã¦ã®æåã使ç¨ã§ãã¦ãã¾ãã¾ãã ãããã¨ã³ã³ã¼ããæ½ããªãã£ãå ´åã ããã°ã©ã ã®ãã¹åã®ä¸é¨ã¨ãã¦ã® 0x20 ãªã®ãã åºåãæåã¨ãã¦ã® 0x20 ãªã®ããåºå¥ã§ããªã ãªã£ã¦ãã¾ãã¾ãã ãã¨ãã£ã¦ãåºåãæåã¨ã㦠0x0 ã使ç¨ããã®ã¯ãã©ã¤ãã©ãªé¢æ°ã使ããªããªãã®ã§ 大混乱ãæããã¨ã容æã«æ³åã§ããã§ãããã > ã«ã¼ãã«å ã«ãã¼ãµã¼ãå ¥ãããã¨ã¯Linusããããã£ã¦ãããã¨ããã£ã¦ãã¿ããªæ°ã«ããã®ã§ > ãã£ã¨è©³ãã説æããæ¹ãããã 0x20ï¼è¦ç´ ã®åºåãï¼ ã¨ 0x0A ï¼è¡ã®åºåãï¼ã ãã§æ©æ¢°çã«ãã¼ã¹ã§ãã TOMOYO 㮠表è¨æ³ã¯ã 0x0 ï¼è¦ç´ ã®åºåãï¼ ã¨ 0x0 0x0 ï¼è¡ã®åºåãï¼ã§ãã¼ã¹ããããã æ±ãããããå®å ¨ã§ãã ãé·ãï¼æååãã§ãã¼ã¹ããæ¹æ³ãããã¾ãããï¼ãã¿ã¼ã³æåãªã©ãå«ãå¯è½æ§ã ããããï¼ ãæååãã®é¨åãæ£ãã表è¨ã«å¾ã£ã¦ãããã®ãã§ãã¯ã¯ã©ã®ã¿ã¡å¿ è¦ã« ãªãã¾ãã TOMOYO ã®æååå¦çé¢æ°ã®æ®ã©ã¯ãæååããã¼ã¹ããå¦çã§ã¯ãªããæååãæ£ããã ã©ããã æ¤è¨¼ããããã«å¿ è¦ã¨ããã¦ãã¾ãã > ãã°ãè¦ã«ãããªãã ãã ã£ããããããªå¦çå ¥ãããªã ãã°ãè¦ã«ãããªãã ããªããããªå¦çãå ¥ããªãã¨ããé¸æè¢ãããã§ããããã TOMOYO ã«é¢ãã¦ã¯ããã°ï¼ãå«ãããã¹ã¦ã®æååï¼ãæ¬ æç¡ãä¿æãã¦ããããã« ä¸å¯æ¬ ãªã®ã§ãã
712 ï¼login:Penguinï¼2009/01/12(æ) 17:41:04 ID:fsX40d3O >>703 ï¼ç¥ï¼ ãã¼ã¨ãåãè¨ãããã£ããã¨ããããã¾ãä¼ãã£ã¦ãªãæ°ãããã ã¾ããã¬ãã¥ã¼ã¯ã¯TOMOYOã®ä»æ§ãªããç¥ãã¾ããããªã®ã§ãã»ã¨ãã©ã®å ´å㯠ããããã£ã¹ã¯ãªãã·ã§ã³ã¨ã³ã¼ããè¦æ¯ã¹ã¦ã¬ãã¥ã¼ãã¾ãã ããã§ãããããã£ã¹ã¯ãªãã·ã§ã³ã«èª¬æããªãå ´åã¯éå»ã®è°è«ã«åºã¥ãã¦å¤æãã¾ãã å¤ãã®å ´åã«ããªã®ã§ããã®ã±ã¼ã¹ã 㨠ï¼ï¼ãã£ã¹ã¯ãªãã·ã§ã³ããªã ï¼ï¼éå»ã«ãã¼ãµã¼ã¯å«ããã¦ãã âï¼ãããNack ã¨ãªãããã«ãèªåããä»åãã¦ããããã§ãã è¨ãããã£ãã®ã¯èª¬å¾ããããã®çè«æ¦è£ ã¯ã©ãã«ãããã§ããï¼ã¨ãããã¨ã§ãã
ããããã£ã¹ã¯ãªãã·ã§ã³ã®æ¸ãæ¹ãæªãã¨ãããã¨ã
704ã®ã¹ã¬ãã
704 ï¼login:Penguinï¼2009/01/12(æ) 16:39:22 ID:SrCsF0ph >>687 > Ingo ãftraceé¢ä¿ã§ãã¡ã¤ã«åãæ£è¦è¡¨ç¾ã§æå®ã§ããããã«ããããã£ã¦ä»¥åãã£ã¦ããããã æ£è¦è¡¨ç¾ã¯æã® AppArmor ã使ã£ã¦ããããã§ããã TOMOYO ã§æ¡ç¨ããã¤ããã¯ããã¾ããã æ£è¦è¡¨ç¾ã®åé¡ç¹ã¨ãã¦ã¯ã ï¼ï¼ï¼è¡¨è¨ãããã°ã©ã æ¯ã«ãã©ãã©ï¼ä¾ãã°ã·ã§ã«ã§ã¯ * ã¯ç¹å¥ãªæå³ãæã¤ã . 㯠æããªãã®ã«å¯¾ãã sed ã§ã¯ . ã¯ç¹æ®ãªæå³ãæã¤ï¼ã§ãããããå©ç¨è ã«å¯¾ã㦠ãäºåã«å ¨ã¦ã®æ£è¦è¡¨ç¾ãç解ãã¦ããã ãã¨ãå¿ è¦ ï¼ï¼ï¼ç¹å¥ãªæå³ãæã¤æåãç¡å¹åããããã«ä½ããã®ç¹å¥ãªæåï¼é常㯠\ ã§ãããï¼ ãæå®ããã¨ãã å®è£ ã ã¨ãå°æ¥æ°ããæå³ãæãããããªã£ãå ´åã«æ¢åã®æååã¨ã® äºææ§ã失ããã¦ãã¾ããããæ©è½ã å¢ããããã«æ¡å¼µãããã¨ãä¸å¯è½ ï¼ï¼ï¼ï¼ï¼ï¼ãçºçããã®ãæãã¦ç¹å¥ãªæå³ãæããªãæåã¾ã§ \ ãæå®ãããã®ã¯ ã¦ã¼ã¶ã«ã¨ã£ã¦ èªã¿ã«ããããã¼ã¹ããå´ã¨ãã¦ãç¡æå³ãªå¦ç ã¨ããã®ãããã¾ãã TOMOYO ã§ã¯ç¹æ®ãªæå㯠\ ã§å§ã¾ãã¨ããå®è£ ã§ããããã ï¼ï¼ï¼å©ç¨è ã¯èªåãç¥ããªããã¿ã¼ã³ã«ééããæã«åãã¦æå³ã調ã¹ãã°ããããã å©ç¨è ã«å¯¾ã㦠ãäºåã«å ¨ã¦ã®æ£è¦è¡¨ç¾ãç解ãã¦ããããã¨ã¯ä¸è¦ ï¼ï¼ï¼æ°ããæ©è½ãæãããããªã£ãå ´å㯠\ ã§å§ã¾ã表è¨ãå®ç¾©ãããã¨ãã§ããã®ã§ã æ¡å¼µã容æ ã¨ããã®ãããã¾ãã >>690 > security_task_free()ã¯Credãªãã¦ãäºå®ä¸ç¡æå³ã ã£ãã¯ããtask struct ã£ã¦RCUã¤ãã£ã¦ã > ã¹ã¬ããæ»ãã ã¨ãã¨ã¯éãã¿ã¤ãã³ã°ã§æ§é ä½ç ´æ£ãã¦ãããããã¨ãã¨ä½¿ãéãªãã¦ç¡ãã£ãã ã¡ã¢ãªã解æ¾ããããã®ããã¯ã¨ããæå³ã§ãã®ã§ãã¹ã¬ãããæ»ãã ã¨ãã« å¼ã°ããªãã¦ãæ§ãã¾ããã ããã¯ãåå¨ãã¦ãããã¨ãéè¦ãªã®ã§ãã > tomoyo_domain_info ã«u32 ã追å ããæ¹å¼ã§ã¯ä½ãå°ãããå ¨ç¶æ¸ãã¦ãªãã®ã§è¿äºã®ãããããªãã¨ããã®ãææ³ã credentials ã«ãã copy on write ã¨ãªã£ããããæ°ãã -ENOMEM ãçºçãã å¯è½æ§ãå¢ãã¾ããã credentials ãç¡ãã£ãæ代ã«ã¯åå¨ããªãã£ã error path ãæ±ãå¿ è¦ãçããããã éæã« if æãå¿ è¦ã«ãªãã¾ãã
713 ï¼login:Penguinï¼2009/01/12(æ) 17:45:52 ID:fsX40d3O >>703 >>704 ï¼> ã«ã¼ãã«å ã«ãã¼ãµã¼ãå ¥ãããã¨ã¯Linusããããã£ã¦ãããã¨ããã£ã¦ãã¿ããªæ°ã«ããã®ã§ ï¼> ãã£ã¨è©³ãã説æããæ¹ãããã ï¼0x20ï¼è¦ç´ ã®åºåãï¼ ã¨ 0x0A ï¼è¡ã®åºåãï¼ã ãã§æ©æ¢°çã«ãã¼ã¹ã§ãã TOMOYO ã®è¡¨è¨æ³ã¯ã ï¼0x0 ï¼è¦ç´ ã®åºåãï¼ ã¨ 0x0 0x0 ï¼è¡ã®åºåãï¼ã§ãã¼ã¹ãããããæ±ãããããå®å ¨ã§ãã ï¼ãé·ãï¼æååãã§ãã¼ã¹ããæ¹æ³ãããã¾ãããï¼ãã¿ã¼ã³æåãªã©ãå«ãå¯è½æ§ãããããï¼ ï¼ãæååãã®é¨åãæ£ãã表è¨ã«å¾ã£ã¦ãããã®ãã§ãã¯ã¯ã©ã®ã¿ã¡å¿ è¦ã«ãªãã¾ãã ããã¯ãè¨æ³ã«TOMOYOã«ã¼ã«ã追å ãããããæ¢åã®ã«ã¼ãã³ã®åå©ç¨ãã§ããªããªã£ã㨠è¨ã£ã¦ãããã§ãããã ãããããã£ã¨è©±ãæ ¹æ¬ã«ãã£ã¦ãã£ã¦ãTOMOYOã«ã¼ã«ããããªãã£ã¦è¨ããããã©ããã¾ãï¼ è³ªåããã¦ãããããã«çããã ãã£ã¦ã®ã¯ããã¼ã¸ã®ä½æ¦ã¨ãã¦çæªã«è¦ãã¦ãã¾ãã¾ãã >>704ã®èª¬æã¯ãå®å ¨ã«TOMOYOè¦ç¹ãªã®ã§ãã«ã¼ãã«éçºè ã®è¦ç¹ã«å¤æããªãã¨èª¬å¾åã ã§ãªãããããªãããªã
ããã§ãTOMOYOè¦ç¹ã§ã¯ãªãã«ã¼ãã«éçºè è¦ç¹ã«ç«ã¦ã¨ããææã
714 ï¼login:Penguin âXkB4aFXBWg ï¼2009/01/12(æ) 17:49:07 ID:PpBaufXM >>710 AppArmorã®d_namespace_pathã¯ã >In AppArmor, we are interested in pathnames relative to the namespace root. >This is the same as d_path() except for the root where the search ends. Add >a function for computing the namespace-relative path. ã¨ããã¨ã§ãd_pathãæ¡å¼µãããã¨ãããã¨ã§d_namespace_pathã¨ãã¦ããããã§ãã rootãè¶ ããnsã¾ã§ã®pathã¨ããæå³ã§ã¯tomoyoãåãããã§ããã d_namespace_pathã«ãã¦ãtomoyoã®realpath(3)ã«ãã¦ããããããã®å®è£ 以å¤ã§ã¯ ï¼ããããï¼ä½¿ãããªãã§ããããAppArmorãtomoyo(ccs)åºæã®å称㫠ããã®ãç¡é£ã§ãããï¼ä»ããã§ããï¼
ä¸è¨ã¯TOMOYOããã¸ã§ã¯ãã®ããã¸ã§ã¯ãããã¼ã¸ã£ã¼ã®ææ³ã(âXkB4aFXBWgã¨ããã®ãã¤ãã¦ããçºè¨ã¯ããã¸ã§ã¯ãããã¼ã¸ã£)
715 ï¼login:Penguin âXkB4aFXBWg ï¼2009/01/12(æ) 17:57:44 ID:PpBaufXM >>701 ããã¨ããè¦ãªãããè²ã ä»ããï¼ãããã¯ä»ããï¼ã¢ã¼ãã«å ¥ã£ã¦ãã¾ãã > éå»ã®ææ¡ã§ã¯ security/tomoyo/ 以ä¸ã ãã®ä¿®æ£ã§æ¸ãããã«ãªã£ã¦ããã >TOMOYO ã使ããªãã«ã¼ãã«ã®ããã«ã³ã¼ãã大ãããªããªãããã«é æ ®ãã¦ãã¾ããã ããã¾ã§lkmlã§ã¬ãã¥ã¼ãã¦ããã人ãã¡ã¯âã®ãã¨ããã¾ãæèãã¦ãªããã㪠æ°ããã¦ãã¾ããããæ°ã®ããï¼ ãã¼ã«ã«ãªããªãã§ãè¯ãã ããã¨ã¯è¨ãã¾ããããã³ã¢ã®ã³ã¼ãã®ä¿®æ£ã¨ lsmã®ã¢ã¸ã¥ã¼ã«ã®ä¿®æ£ï¼è¿½å ï¼ã§ã¯æå³ã¨å½±é¿ç¯å²ãéãããã§ã ãããèªèããã¦ããªãããå¿ è¦ä»¥ä¸ã«å³ããè¦ããã¦ãããããªã 716 ï¼login:Penguin âXkB4aFXBWg ï¼2009/01/12(æ) 18:19:30 ID:PpBaufXM >>686 >åã®ææ³ã§ã¯ãããã«ããã°ãè¦ã«ãããªãã ãã ã£ããããããªå¦çå ¥ãããªãã¨ããã®ãå ±éèªèã ã¨æã ï¼ç¥ï¼ >>703 ã«æ¸ããã¦ããããã«ããã°ãè¦ããããããããã§ã¯ãªãã¨ããã®ãã¾ãããã¾ãã >crazy ãªãã¡ã¤ã«åã«å¯¾ãã¦ã¨ã³ã³ã¼ããæ½ããªãã¨ã©ããã¦safeã§ãªããªãã®ã説æããã¦ããªãã >ã«ã¼ãã«å ã«ãã¼ãµã¼ãå ¥ãããã¨ã¯Linusããããã£ã¦ãããã¨ããã£ã¦ãã¿ããªæ°ã«ããã®ã§ >ãã£ã¨è©³ãã説æããæ¹ãããã descriptionã§ä»¥ä¸ã®å 容ã強調ããã»ããè¯ãã¨æãã¾ããã ã»tomoyoã§ã¯ããªã·ã¼ã®ä»æ§ã¨ãã¦ã0x20ãå«ãå ¨ã¦ã®ãã£ã©ã¯ã¿ã¼ã使ãããã¨ã ãç®æããï¼SELinuxã§ã¯ããã§ã¯ããã¾ããï¼ ã»ãã®ããã«ãã¹åã®æ§æè¦ç´ ã®æ£è¦åãè¡ã£ã¦ãã 717 ï¼login:Penguin âXkB4aFXBWg ï¼2009/01/12(æ) 18:29:33 ID:PpBaufXM >>709 ï¼ç¥ï¼ >ãã¡ãªããããªããã°ã³ã¼ã追å ããªããã¨ãã価å¤è¦³ãåæã«çè«æ¦è£ ãã¦èª¬å¾ããã®ãããã¨æãã åæã§ãã ãã ãåæ¹åãªã¹ãã使ãã¨ãread lockãã¤ããªãã¨ãããªãããå¹çã¯è½ã¡ãã ããã«ã¯å°æ¥tomoyoããã«æ©è½ã«ããã¨ãã«ããã¯ã«ãªãã¨ãããã¨ã§ã å çããããå¤ããããªãæ°æã¡ãæ³åã¯ã¤ãã¾ãã ããã¯æ¬å½ã«æ©ã¾ããã§ãã 718 ï¼login:Penguinï¼2009/01/12(æ) 18:56:00 ID:fsX40d3O >>715 ï¼> éå»ã®ææ¡ã§ã¯ security/tomoyo/ 以ä¸ã ãã®ä¿®æ£ã§æ¸ãããã«ãªã£ã¦ããã ï¼>TOMOYO ã使ããªãã«ã¼ãã«ã®ããã«ã³ã¼ãã大ãããªããªãããã«é æ ®ãã¦ãã¾ããã ï¼ããã¾ã§lkmlã§ã¬ãã¥ã¼ãã¦ããã人ãã¡ã¯âã®ãã¨ããã¾ãæèãã¦ãªããã㪠ï¼æ°ããã¦ãã¾ããããæ°ã®ããï¼ ãã¼ã¨ãæ¹ãã¦æ¸ãã¾ã§ããªãã¨æãããã©ããåºæ¬ã«ã¼ã«ã¯ ã»TOMOYOã«ã¼ã«ã¯tomoyoãã£ã¬ã¯ããªã«ãã ã»å ±éã«ã¼ã«ã¯å ±éé¨ã«ãã ãã¨ã ãã§ãå ±éå¦çã«ã§ããã£ã½ãã®ãsecurity/tomoyoã«ãã£ãããåå©ç¨ã§ããªããã ãªã®ããå ±éé¨ã«ãã£ãããã㨠ã¬ãã¥ã¼éããªãã ãªã®ã§ãã¬ãã¥ã¼ã¯ã¼ã¯ä¸è²«ãã¦ãã¨æããã TOMOYOã®ä»ã®å®è£ ãæªãã¨ã¯ãããªããã説å¾ã®ãããããã ã£ã¦ãããä½ã£ã¡ãã£ãã ã ãããçãªèª¬å¾ã«ãªã£ã¦ãã ã±ã¼ã¹ãããã®ãããããªãã¨æãã TOMOYOã®ã¬ãã¥ã¼ã®åãçãã§ãã£ã¦ããTOMOYOã®äºæ ã説æããã®ã¯ãå®ã¯çç±ã« ãªã£ã¦ãªããã ãã TOMOYOã®ä»æ§å¤ããã°è§£æ±ºãªã®ããã£ã¦ç¸æã¯æãããã ã«ã¼ãã«å ¨ä½ã§è¦ãã¨ãã«ã©ã£ã¡ãããããã£ã¦è°è«ã®ã¡ã¿ã¬ãã«ãï¼æ®µéããã¦ã 大çã®æ¹åæ§ãåæããå¾ãã¯ãã«ã«ãªè°è«ã«è½ã¨ãã¦ããã®ãå®ç³ã ã¨æãã
è°è«ã®æ¹åæ§ã説å¾ã®ä»æ¹ã®ããã¯ãææãã¦ããããããã ã
å
ã«å®è£
ãä½ã£ã¦ããããå
ã«èª¬å¾ãå§ããã¨ããã®ã¯å
¸åçãªæªããã¿ã¼ã³ãªãã ãã©ãä¼æ¥çºã®ãªã¼ãã³ã½ã¼ã¹ã®å ´åããã¼ãã¼ã®ãå¾ã
ã«ãã¦ããã
ãã¼ãã¼ã®ã«ããããªãããã«ããããã«ãå®è£
ãããåã«ãã³ãã¥ããã£ã«ããã¨ããæ©è½ã追å ããããã ãã©ããã¨ããRequest for Comments (RFC)ã¿ãããªææ¸ãæµãã®ãçéã§ããã
ã ãã©ãå
ã«ä½ã£ã¡ãã£ããã ãããä»æ§ãå¤ãã¦ã§ãè°è«ãããããªãã
719 ï¼login:Penguin âXkB4aFXBWg ï¼2009/01/12(æ) 19:07:54 ID:PpBaufXM >>705 >David Howells ã¯çµ¶å¯¾TOMOYOã«è¯ãæ¹åã«ã³ã¡ã³ããã¦ãããããäºåã«ãã´ã£ã¦ããã®ï¼ >ã§ããªããã°ããã£ããDavidã¯å¿ãã¦Sergeæ»ç¥ããã»ãããããªãï¼ ãã´ã£ã¦ããã¨ããããã¯ããã©ã¤ãã¼ãã¡ã¼ã«ã§èª¿æ´ããçµæã«åºã¥ãã ãããã«ãªã£ã¦ãã¦ãtomoyoå´ï¼ãããã¯tomoyoåç¬ã®ï¼å¸æãææ¡ã§ã¯ ãªãã®ã§ãããã ããã©ã¤ãã¼ãã¡ã¼ã«ã§ãã®ãã¨ãLKMLã«ã¯è¨¼è·¡ã¨ãã¦æ®ã£ã¦ãã¾ããã ã¹ã¬ããã§ãDavidã«å¼ã³ããã¦ããã®ã¯ããããããã®éããªãã ããç㪠ä¸ç¨®è£ä»ããæå¾ ãã¦ãã¾ãã Sergeã¯ä½ãå°éãããããªããããè²ã ãªã¨ããã«é¡ãåºãã¦ãã ã¨ãã¹ãã¼ãã§ã¯ããã¨ãã®é¨åã«ã¤ãã¦ã¯Davidãå çãç解ãã¦ããã»ã©ã«ã¯ å 容ãããããã£ã¦ããªãããã§ããããã®æå³ã§ãcredentialã®ææ¡è ã§ãã Davidã®çºè¨ãå¾ ã£ã¦ãã¾ããããæ¸ãã¦ãããªãã®ã§ã¬ã¹ãã¤ãã¦ã Davidã«ãã®å 容ãè£ä»ããã¦æ¬²ããã¨å¾ ã£ã¦ãããããªç¶æ³ã§ãã 722 ï¼login:Penguinï¼2009/01/12(æ) 19:20:09 ID:fsX40d3O ã¡ãã£ã¨ãç¹°ãè¿ãã«ãªãããã©ããåã®ã¬ãã¥ã¼ã¯ã¼ã¨ãã¦ã®è¦ç¹ã§ã¿ãã¨TOMOYOã¯æèã« ãã ãããæã¡ãããã®ãæªãå¾åãã¨æãã TOMOYOã®ãã¼ã³ã³ã»ããã¯ããã¹åãã¼ã¹ã®ã»ãã¥ãªãã£ã¼ã¢ã¸ã¥ã¼ã«ãã§ããã ãã®ã³ã³ã»ãã㯠ã¿ããªNackãã¦ããªãã®ã§ããã¤ãã¼ã¸ããã¦ããããããªãç¶æ³ã ãã®ãã¼ã³ã³ã»ããã®ç¯å²ã§ã¯VFSã ã£ã¦å¤ããããã ãããã®ã³ã³ã»ããã®ç¯å²ã§ã¯ã ããªãå¼·ãç«å ´ã§äº¤æ¸ã§ããç¶æ³ã ãªã®ã«ããã¼ã¸ãããªãã®ã¯ãã¼ã³ã³ã»ãã以å¤ã«åé¡ã®ããã³ã¼ããå¤ãã ã»list1ã¯TOMOYOã®ãã¼ã³ã³ã»ãããªã®ã ã»d_realpathï¼ï¼ãã¼ã³ã³ã»ãããªã®ã ã»ä»ã®ãã¹åã®TOMOYOè¨æ³ã¯ãã¼ã³ã³ã»ãããªã®ã ã¨èããããå ¨é¨NOã§ãããã list1æ¨ã¦ã¦ãå®è£ ã§ããããä»ã®è¨æ³ãæ¨ã¦ã¦ãããã¹åãã¼ã¹ã®ã»ãã¥ãªãã£ã㯠åºæ¥ãããã¡ãã£ã¨ä¾¿å©ç¨åº¦ããã ã¬ãã¥ã¼ã¯ã¼ããè¦ãã¨åå©ç¨æ§ãæ¨ã¦ãã ãã® ã¡ãªãããããªãããå´ä¸ãªãã ãã d_realpath()ã¯ã¾ã£ãããã¡ãããªããã©ãTOMOYO以å¤ã使ãããããã«æ±ç¨åããªãã¨ã ã¡ãã£ã¨è«å¤ã£ã½ãã éå»ã®çºè¨ã¿ãããã¦ã¿ãã¨ãTOMOYOãã¼ã ã質åããã£ã¦ãããã«å¯¾ãã¦TOMOYOã®äºæ ã 説æããã¨ãã« ç¸æãè¿äºãã¦ãªãã±ã¼ã¹ãããªãããã ããã¯OKãããªãã¦ãæ¶æ¥µçå対ã£ã¦ã®ã¯ç解ãã¨ããã»ããããã ä¸åº¦ä»æ§ãããã£ã¨ãã£ã¨åã£ã¦ããã¼ã¸ããã¦ããæ¹åããæ¹ãåã¯æ¼ãã ä»ã®ã³ã¼ãã ã¨ãåãã¬ãã¥ã¼ã¯ã¼ãªãNackããã
ãã¼ã³ã³ã»ããã¯ä½ãããã以å¤ã®ãã®ã¯ã°ã£ããåé¤ã
723 ï¼login:Penguinï¼2009/01/12(æ) 19:33:24 ID:fsX40d3O ãªãã段éçéçºãæ¼ããã¨ããã¨çç±ãï¼ã¤ãã£ã¦ ï¼ï¼ï¼Andi Kleenã®åã売ãã«ãªããã©ï¼ãããã¯è«æãæ¸ãããã«æ¸ãã¹ãã ã¨ããã®ãããã ã»ãã¥ãªãã£ã®è«æã§ãã©ã£ã¡ãå®å ¨ãè°è«ãã¦ãããã¼ãã¼ã§ãã¨ããã§ãslistã使ã㨠å¹çãããã¦ã»ã»ãªãã¦æ¸ããããã©ã®æå°æå®ã§ã絶対å´ä¸ããã ã¤ã¾ãããã¾ãã£ã¦ããã®ã¯ããããããã¨ã æ°ããã³ã³ã»ãããä¸ã«åãã¦ããã¨ãã«ãéãæèãæ··ããã®ã¯çæª ï¼ï¼ä¸åº¦ããã¦ããã£ã¹ããªã«å·»ããã¦ããã®æ¹ããTOMOYOã¯ãããªã«å¤ãã®ã¦ã¼ã¶ã« 使ããã¦ããã®ã§ ã³ã¢é¨åãå¤ãã¦ã§ãæ¹åãã価å¤ããããã ã¼ã¼ ã¨ããè«æ³ã使ããããã«ãªããããã¯å¤§ããã ã¬ãã¥ã¼ã¯ã¼ã¯ã³ã¹ãã¨ãããã£ããã®å¤©ç§¤ã§ãã§ãã¯ãã¦ããã®ã§ãã³ã¹ããåããªã ã³ã¹ãï¼çµ¶å¯¾å¿ è¦ãªæ©è½ï¼ãªã ãããã£ãããããããããªã
ãªãã段éçéçºãåããã¨ããçç±ãææãã¦ãããç´ æ´ãããã
724 ï¼login:Penguinï¼2009/01/12(æ) 19:43:48 ID:fsX40d3O >>719 ï¼>David Howells ã¯çµ¶å¯¾TOMOYOã«è¯ãæ¹åã«ã³ã¡ã³ããã¦ãããããäºåã«ãã´ã£ã¦ ããã®ï¼ ï¼>ã§ããªããã°ããã£ããDavidã¯å¿ãã¦Sergeæ»ç¥ããã»ãããããªãï¼ ï¼ãã´ã£ã¦ããã¨ããããã¯ããã©ã¤ãã¼ãã¡ã¼ã«ã§èª¿æ´ããçµæã«åºã¥ãã ï¼ãããã«ãªã£ã¦ãã¦ãtomoyoå´ï¼ãããã¯tomoyoåç¬ã®ï¼å¸æãææ¡ã§ã¯ ï¼ï¼ãªãã®ã§ãããã ããã©ã¤ãã¼ãã¡ã¼ã«ã§ãã®ãã¨ãLKMLã«ã¯è¨¼è·¡ã¨ãã¦æ®ã£ã¦ãã¾ããã ï¼ã¹ã¬ããã§ãDavidã«å¼ã³ããã¦ããã®ã¯ããããããã®éããªãã ããç㪠ï¼ä¸ç¨®è£ä»ããæå¾ ãã¦ãã¾ãã ã¾ãã人ã®å¥½æãåæã«ããä½æ¦ã¯çæªã Davidã®ç«å ´ããããããããã§TOMOYOã«ä¸ããã¨èªåã責任ãã¨ããã¨å®£è¨ãã形㫠ãªã£ã¦ãã¾ããããç¸æãå°ããã話ã®ãã£ã¦ããããã èªåèªèº«ã®èª¬å¾ã§ãï¼å²æ¹èª¬å¾ã§ããå¾ã«ããªã¬ãããã§ããã¨æãããã¨ããããç¨åº¦ã®æ¯æ´ ããæå¾ ãã¡ããã¡ã ã¨æã ï¼Sergeã¯ä½ãå°éãããããªããããè²ã ãªã¨ããã«é¡ãåºãã¦ãã ï¼ã¨ãã¹ãã¼ãã§ãã ã¯ã¯ã¯ãç¥ã£ã¦ã¾ãã ï¼ãããããã¨ãã®é¨åã«ã¤ãã¦ã¯Davidãå çãç解ãã¦ããã»ã©ã«ã¯ ï¼å 容ãããããã£ã¦ããªãããã§ããããã®æå³ã§ãcredentialã®ææ¡è ã§ãã ï¼Davidã®çºè¨ãå¾ ã£ã¦ãã¾ããããæ¸ãã¦ãããªãã®ã§ã¬ã¹ãã¤ãã¦ã ï¼Davidã«ãã®å 容ãè£ä»ããã¦æ¬²ããã¨å¾ ã£ã¦ãããããªç¶æ³ã§ãã ããã¯çæªã åãã£ã¦ããããªãã®ã¯èª¬æã®ä»æ¹ãæªããã¨ããã®ãè°è«ã®åºçºç¹ã«ãã¹ãã Sergeã®ãããªè²ã ãã£ã¦ã人ã¯å ¨é¨ç´°ããã¯è¦åããªããããããä½ã人ã説æããã®ã¯ 大åæã«ãªããã ã誰ã ãããè¨ãã¾ãããã¯çç±ã¨ãã¦å¼±ãããã®ã§ãTOMOYOã«éãããã«ã¼ãã«å ¨ä½ã èããä¸ã§ãä»ã®ä»æ§ããããã¨ããçè«çã«èª¬æã§ããå¿ è¦ãããã ã©ããã¦ããã¡ãªããåæ ã¨å¥½æã«ããã£ã¦ããããã©ãããã¯æå¾ã®æ段ãããªãããªã
TOMOYOã®ã¢ã³ããã¿ã¼ã³ãããã§ããããã§ããã¨ææããã¬ãã¥ã¢ã¼ãæã®ããã£ãææããããã
725 ï¼login:Penguin âXkB4aFXBWg ï¼2009/01/12(æ) 19:55:24 ID:PpBaufXM >>724 ï¼ç¥ï¼ ãã®æå³ã§ã¯èª¬æèªä½ãDavidã«ãµã£ã¦ããæèã¯ãªãã¦ãå¿ è¦ãªå 容ï¼èª¬æï¼ã¯ æ¸ãã¦ãã£ã¦ãSergeãã¡ããã¨ããã£ã¦ãããã°ï¼ç¬ï¼ããªãã»ã©ã㨠æã£ã¦ãããã¯ããªãã§ãã ï¼Davidãè£ä»ããã¦ããããããããããã©ãå¿ é ã§ã¯ãªãã¦ãé ¼ãåã£ã¦ããããã§ããªãï¼ ã¨ãããµãã«ã¿ãæãç¾ç¶ã®èª¬æã£ã¦ãã¯ãä¸è¶³ãã¦ããã¨æããã¾ããï¼ 726 ï¼login:Penguin âXkB4aFXBWg ï¼2009/01/12(æ) 20:31:01 ID:PpBaufXM >>722 ï¼ç¥ï¼ ããã¸ã§ã¯ããå§ããé ã¯ãæåéã夢ã«ãã¡ã¤ã³ã©ã¤ã³ã®ãã¨ã¯èãã¦ãã¾ããã§ããã CELF, YLUGã®ã·ã§ãã¯ãçµã¦ææ¦ãããã¨ã«ããã¨ãããæ¬å½ã«ãããå¯è½ã¨ã¯ æã£ã¦ãã¾ããã§ããï¼æãã¾ããã§ããï¼ãã§ããããç®æãã¹ããã¨ã 㨠æãã¦ããã£ãã®ã§ãææ¦ãå§ãã¾ããããããããã°ãã¼ã¸ãããããããããªãã¾ã¾ã æ稿ãç¹°ãè¿ãã¦ãã¾ããã ãããLSMã®ããã¯ããã¼ã¸ãããã¾ãæ¨æ¥ããã®ããã®ããã¨ããè¦ã¦ãã¦ã ããããã¦ãããããããæ¬å½ã«æãå±ãã¨ããã«ããããã£ã¨æ¥ããããã ã㨠æãã¾ãããå¤ãªè¨ãæ¹ã§ãããæéã®åªåã¨ä½æ¥ã§ãªãã¨ããªãã¨ããã«ããããã®ã 㨠æãã¾ããï¼ä»ã¾ã§ã¯ããã§ã¯ãªãã£ãã®ã§ãï¼ã ææ¥ãä¸ã®äººä¼è°ã§è©±ãåã£ã¦ã¿ã¾ãããã§ãããã¨ãªããããã¨ãããå½å ã® æ¹ã ã«ãè¦ã¦ããã£ã¦ãããã§ããããã¨ãããéããã¨è¨ããããããã«ã㦠ææ¦ã§ãããã¨æãã¾ãã
éåé ãã¾ã§æ¥ã¾ãããã¨ããææ ¨æ·±ãã³ã¡ã³ãã§ãããéé²ã«ææ¢ãç¶æ ã§ããã¾ã§æ¥ããããããã°ã£ãããããããããã°ããªãã¦ããããããç¸æã説å¾ããæ¹æ³ãééãã¦ããããã§ãå¤åãä»ã®çµé¨å¤ã§TOMOYOãåè¨è¨ããã°ãã£ã¨ããéã«ãã¼ã¸ãããã¨æãããã®çµé¨ã¯è²´éã ã¨æãã試è¡é¯èª¤ã®ãªãã§ç²å¾ããããããã¨ã ã¨æãã
727 ï¼login:Penguin âXkB4aFXBWg ï¼2009/01/12(æ) 21:44:25 ID:PpBaufXM ãããæ®æ®µLKMLãèªãã§ããªã人ã§ãéå»ã®è°è«ãè¦ããã¨ããå ´åã«ã¯ã æ稿ãã¨ã®ãªã³ã¯ã以ä¸ã«ã¾ã¨ãã¦ããã¾ãã®ã§ãå©ç¨ãã ããã ttp://tomoyo.sourceforge.jp/wiki-e/?WhatIs#mainlining ããããã®ãªã³ã¯ã¯LWN.netãããããã«ãªã£ã¦ãã¾ããä½æ LWW.netãã¨ãã㨠Linuxå ¬å¼ãã¥ã¼ã¹ãµã¤ãã«ããå®ç¹è¦³æ¸¬ï¼ã®ã¤ããã§ã ããããã®è¨äºã«ã¯è°è«ã®ã¹ã¬ããã¸ã®ãªã³ã¯ãããã®ã§ããããéã㨠ã¹ã¬ããããã©ãã¾ããæ¬å½ã¯LKMLã¸ã®æ稿ã®ä»ã«fsdevãªã©ã§ã®è°è«ã ãã£ãã®ã§ããï¼ç¹ã«åæï¼ããã¡ãã¯ã«ãã¼ãã¦ãã¾ããã
http://tomoyo.sourceforge.jp/wiki-e/?WhatIs#mainlining
ãç°¡æ½ã«ã¾ã¨ãããã¦ããã
728 ï¼ãã ãããããï¼2009/01/12(æ) 23:06:20 ID:TfRewdK6 >>701 ï¼ç¥ï¼ éå»ãã°å¼ã£å¼µãåºãã¦ææ§ãªè¨æ¶ã¯ç¡ããã¦ããæ¹ããããã§ãï¼ å¼ç¨ãªã³ã¯ããã«ãºããºãè²¼ãã¨ã >>722 ï¼ä¸åº¦ä»æ§ãããã£ã¨ãã£ã¨åã£ã¦ããã¼ã¸ããã¦ããæ¹åããæ¹ãåã¯æ¼ãã ï¼ä»ã®ã³ã¼ãã ã¨ãåãã¬ãã¥ã¼ã¯ã¼ãªãNackããã ããã¾ã§ãã¦ã°ã£ããåã£ã¦ã³ã¼ãå¤ããã°ãã¾ãèªã¿ç´ãã¨ã㧠ã¡ã³ããããæ¹ããããã°ããã©ããªãã¢ããã®ï¼ ç¸æãããããããã®ã¾ã¾ç¹æ»æ»ï¼ç¬ï¼ããã¦ãããæ¹ããããã é·ãç®ã§è¦ããªãä»ã®ã¾ã¾ã®æ¹ãããæ°ããã ããã§ã°ã£ããåé¤ãã¦ä»®ã«å ¥ã£ãã¨ãã¦ã 第ä¸è ããã¿ãã°å°è±¡æªããã§ãï¼ SELinuxé£ã¨åå¼ãã£ãã®ãã¨ãããããããªæ £ä¾åä¾ã«çµå±æ ¹è² ãããã®ãã¨ã ããããæããè¡°éã®ç¬¬ä¸ç« ã ããããå§ã¾ã£ã¦ãããªæ°ã駿河ãããããçæ³è«ãã®ã ãããLKMLã¯éã¶é¢ã¿ããã ã ã¡ã³ããï¼å®åãLKML=çåºããããæãã人ï¼æ¿çã«æ³æ¡éãã¦ãããããæ¿æ²»ã´ããå°æ¹è°å¡ ttp://jp.youtube.com/watch?v=HJoFM8ynyMQ é©å½æ¦å£«ã¯ãã«ã¡ãããã¶ããä¸ç¹çªç ´çã«çªè²«ï¼ãæ®²æ» ããï¼ãæ®²æ» ããï¼ 730 ï¼login:Penguin âXkB4aFXBWg ï¼2009/01/12(æ) 23:47:55 ID:PpBaufXM >>729 ã»ã»ã»ããã帰ã£ã¦ããã®ã§å¦ãªè¦éãæ¹ããªãã§ã大ä¸å¤«ã»ã»ã» å ¨é¨ãå ¨é¨ãã³ã¡ã³ããåæ ããããã«ã¯ãããªãããããããããã㯠ããã§ãã¾ããããªãã¨æãã¾ãããpatch descriptionãã³ã¡ã³ãã è¦ç´ããªã©ã¯ããã¹ãã ãããªã¹ãã«é¢ããã³ã¡ã³ããããã£ããæè¦ãåèã« ããããã¦è©±ãåã£ã¦ã¿ã¾ãï¼ãããããã¦ãã¨ããã®ã¯ãä¸ã§ã¯æ¯æ¥ã®ããã« ãããã話ãåãããã¦ããããã§ãï¼ 731 ï¼login:Penguin âXkB4aFXBWg ï¼2009/01/12(æ) 23:59:52 ID:PpBaufXM >>729 ãããã®15%ã¯æ¥æ¬çºã¨ãããã¼ã¿ãããã¾ããLinux Foundation Japanã®ãµã¤ãã«ã¯ tomoyoãããã£ã¨æ©ãããã«ã¼ãã«éçºã«é¢ãã£ã¦ããæ¹ã ã®è¬æ¼ã®è¨é²ãæ®ã£ã¦ããã ã¡ã¤ã³ã©ã¤ã³åã®åãçµã¿ã®æåã¯ãããã®æ å ±ãå¦ã¶ãã¨ã§ããã ttp://jp.linuxfoundation.org/?q=node/121 ããããå éã®å©è¨ã¯æ´»ãããå¯è½ã§ããã°ã¬ãã¥ã¼ããããã£ããã®ã æ¥æ¬çºã®æ¡å¼µã¨ãã¦ææ¡ã§ããã°ãã¨æã£ãããã§ãã 732 ï¼login:Penguin âXkB4aFXBWg ï¼2009/01/13(ç«) 00:08:17 ID:bjWNziJ3 >>728 >å¼ç¨ãªã³ã¯ããã«ãºããºãè²¼ãã¨ã å¯è½ãªã®ã§ãããæ稿ãã¦ããå 容ï¼ç¯å²ã¨ã¢ããã¼ãï¼ãã³ã¡ã³ããã¦ããç¸æ ï¼ã¨ã³ã¡ã³ãã®çµç·¯ï¼ãªã©ãéãã®ã§ããã®çºè¨ã®é¨åãã ãããæ½åºã㦠並ã¹ã¦ãã¡ãã£ã¨é£ããããããã¾ããã >ããã¾ã§ãã¦ã°ã£ããåã£ã¦ã³ã¼ãå¤ããã°ãã¾ãèªã¿ç´ãã¨ã㧠>ã¡ã³ããããæ¹ããããã°ããã©ããªãã¢ããã®ï¼ æ®éãªããã£ã¨ãããªãã§ãããããã¾ã§ã®çµé¨ããè¨ãã¨ã ãé¢åãã¨ããä½åãæ稿ãããªãã¨ãã¯è¨ãããªããããªæ°ããã¾ãã ãä½åº¦ã§ãææ¦ã¯åãã¦ç«ã¤ããçãªå°è±¡ã§ãã ãå¹ççã«åæãããææ¡ã®ä»æ¹ãã§ããªããèãã¦ããã¨ããã§ãã
ç¸æã説å¾ããæã®ã¢ã³ããã¿ã¼ã³ï¼çã®æªãæ¹æ³ï¼ã¨ãçã®ãããã¹ããã©ã¯ãã£ã¹ãã¾ã¨ããã®ã¯éè¦ãªãã¨ãã¨æããTOMOYOãçµé¨ããã¢ã³ããã¿ã¼ã³ã¨ãã¹ããã©ã¯ãã£ã¹ã¯ééããªããã¶ã¼ã«åãªã¼ãã³ã½ã¼ã¹ã½ããã¦ã§ã¢éçºã®æ¹æ³è«ã¨ãã¦éè¦ãªæ å ±ã«ãªããã³ãã¥ããã£ã¨ã®ããã¨ãã¨ããæ¹æ³è«ãã¾ã¨ãããã¨ã¯çµ¶å¯¾ç¡é§ã§ã¯ãªãã
èªåã®é½åãæ¼ãä»ããªããã³ãã¥ããã£å ¨ä½ã«åã£ã¦å©çã®ãããã¨ãææ¡ãããå®è£ ã¯å¤æ´ãããã¨ãèºèºããªãã
ãã®ãããªåçååãå¦ã¶å¤§å¤è²´éãªçµé¨ã ã£ãã¨æããããããããã第ä¸è ãçä¼¼ä½é¨ã§ããã¨ããã®ãæ å ±ã®å ¬éã«ãã£ã¦ã ããªã¼ãã³ã½ã¼ã¹ã£ã¦ããããã
733 ï¼login:Penguinï¼2009/01/13(ç«) 00:11:37 ID:g0j2pveV >>725 æãã ã¾ããæåã® >Serge, > >James is now reviewing TOMOYO Linux patch and he is caring about >your comment below. > >Serge E. Hallyn wrote: >> I don't like the 'in_exec' bit in the task_struct, but adding LSM hooks >> to let just TOMOYO mark whether you're in exec seems even uglier. > >Let me (once again) ask your comment on 'in_exec' approach >originally suggested by David Howells ( http://lkml.org/lkml/2008/10/2/127 ). ã¨ããã®ã¯çµæ§ã²ã©ãã¦ãSergeã¿ãããªå¤å¿ãªäººã ã¨ä»¥åã®è°è«ãå ¨é¨è¦ãã¦ããªã㦠ãããããªãããç¸æã«æéãã¨ããã¦ããã®ããããªã話ã®ãã£ã¦ããããã ã¨ãããã ã§ããã®æ°åãã¨ã® No. TOMOYO refuses to check read permission in security_dentry_open() if current->in_execve is set. ã§å§ã¾ãã¡ã¼ã«ã¯TOMOYOã®èª¬æã§ãããªãã¦ããªãã§ã«ã¼ãã«ã¢ã¼ããã¯ãã£ã¼ã® 観ç¹ããå ¨è¬çã«ã¿ã¦ããã£ã¡ã®ã»ããããã®ãã¨ãã説æã«ãªã£ã¦ããªãã ãªã®ã§ããåã®ããã«å¤æ´ãããã¯æªãããããã¿ããªã®ããã«å¤æ´ããã ã¯è¯ãããããã®ååã«ããããå¦å®çãªåå¿ãããã ããã¨ã«ãªãã 734 ï¼login:Penguinï¼2009/01/13(ç«) 00:14:19 ID:g0j2pveV >>711 ããã¯ãèãç´ãã¦ãã¦ãã¡ãã£ã¨æè¦ãå¤ãã£ãã ããããrealpath()ã©ã¤ã¯ãªé¢æ°ãã¤ãããã¨ãç®çãããªããTOMOYOä¾åé¨ã¨ å ±éé¨ãåãé¢ããã¨ãç®çãªãã ããé¢æ°ã¤ã³ã¿ã¼ãã§ã¼ã¹ãï¼ããèãç´ããã ã©ãã ããï¼ realpath()ã«ãã ãã£ã¦ããéããTOMOYOä¾åé¨ã¨å ±éé¨ããã¾ãåãé¢ããªãã® ãããããªãã 736 ï¼login:Penguinï¼2009/01/13(ç«) 00:24:09 ID:g0j2pveV ãã¨ãããã§ãã ã¬ãã¥ã¼ã¯ã¼ã¯å¤§ãªãå°ãªãã好ãå«ããããã®ã§ãç´å¾ã§ããªãææããã ããã¨ãå¤ã ãããã©ã 絶対è²ããªããã¼ã³ã³ã»ãã以å¤ã¯è¨ããã¨èããæ¹ ãããã§ãã ããã§ãªãã¨ãTOMOYOãã¬ãã¥ã¼ãã¦ãããããå人æ»æãããã¯ææã¯ç¡è¦ ããããã§æ£ã ã ã£ãããã£ã¦æãåºãæ®ãã ããããã¨é·æçã«è¦ã¦ãå³æ¹ãã©ãã©ãæ¸ã£ã¦ããã ã¬ãã¥ã¼ã¯ããã¦ãªãã ãã éå»ã®ã¡ã¼ã«ãèªã¿è¿ãã¦ãè°è«ã®æå¾ãç¸æã®"makes sense"ã¨ã"looks good"ã¨ã"agreed"ã¨ãããåèªã§ çµãã£ã¦ãªãã®ã¯è°è«ã失æãã¦ããã®ã§ã æåãã¦ããã¨ãã¨å¤±æãã¦ããæã¨ã®å·®ã¯èªã¿è¿ãã¦ç¢ºèªãã¦ã¿ãã®ãã ãªã¹ã¹ã¡
ã¬ãã¥ã¼ã¯ããã¦ãªãã
éå»ã¡ã¼ã«ãèªã¿è¿ããè°è«ãæåãã¦ããã失æãã¦ããããããã確èªããã
737 ï¼login:Penguinï¼2009/01/13(ç«) 00:32:06 ID:g0j2pveV ãã¨ã¯è°è«ã®ãã¯ããã¯ã®åé¡ã¨ãã¦ããç§ã¯æ£ããããªããªãã»ã»ãã¨ããã®ã¯ è¯ããªãã¹ã¿ã¤ã«ã æçµçã«èªåãæ£ããã£ãã¨ãã¦ããè°è«ã«è² ããæ¹ããããªæ°æã¡ã«ãªãã®ã§ ããã¦ãªãã®ååã«åããã çµæ§TOMOYOãã¼ã ã¯å¤ç¨ãã¦ãã®ã§æ°ã«ãªã£ãã æåã«ãèªåãèããã¨ãããé¸æè¢ãï¼ï¼ï¼åããã¦ãããããã®Pros, Consã 説æãã¦ããã®ä¸ã§æ¤è¨ããçµæï½ï½çªãããã¨ããçµè«ã«éãããçãªããããã ããã»ãããã¬ãã¥ã¼ã¯ãåæããã£ã¦ãããã©ããã¨ã ãããã観ç¹ã§ã¸ã£ãã¸ã¡ã³ãã§ããããä¸ç·ã«èãããçãªæ¹åã«è©±ãèªå°ãããã㦠ãªã¹ã¹ã¡ ä»ã®é¸æè¢ããªãã¨ããªããã³ã¼ããæ±ãã¦æ°ã«ãããªããããä»ã®é¸æè¢èãã¦ã¿ã¦ã ã¨ããã³ã¡ã³ãã®ã¤ããããæããããã¨æã
ããã¦ãªãã®ååã«åããä¾ããªãã»ã©ãããä¾ã示ãã¦ãããããããªã
738 ï¼login:Penguinï¼2009/01/13(ç«) 00:37:08 ID:g0j2pveV ãã¨ã¯ãããããã¼ãµã¼ãtomoyoãã£ã¬ã¯ããªã«ããã¨ã延ã ã¨æå¥ãããã ãªã®ã§ãã¿ãã°ãçµãç¸æãé å¼µã£ã¦ãããã¦ã ï¼äººä»¥ä¸ã¤ãã£ã¦ãããã libã«ããããããã¨ãããªã¢ã¯ã·ã§ã³ãã¨ããããããã¼ããã¼é¸ã³ããã£ã¨ çå£ã«ããã¹ã㨠æã£ãã ã§ããã¼ããã¼é¸ã³ãèããã¨ãä»ã®ï¼´ï¼¯ï¼ï¼¯ï¼¹ï¼¯è¨æ³ã¯ç¹æ®ãããã®ã§ãè¨ æ³ã®å¤æ´ãããç¨åº¦ã¯è¦æããã»ããããã¨æãã
ä»æ§ã®å¤æ´ããã¨ããªãã
744 ï¼login:Penguin âXkB4aFXBWg ï¼2009/01/13(ç«) 07:43:50 ID:bjWNziJ3 ã¿ãªããããããã¨ããããã¾ãã ã©ããªäººãã©ã®ããããã¦ããã®ããããã¾ãããã ãã¤ã®ã¾ã«ãæã£ã¦ããããå¤ãã®äººãã¡ãæ°ã«ãã¦ãå¿æ´ãã¦ããã¦ããã®ã ã¨æãã¾ã ä¸ç¨®ãå æ°çãåãã¦ããã£ã¦ããæ°ããã¾ã èªåã«ã¯å¤¢ããã£ã¦ããã¤ãæ¬å½ã«ãã¼ã¸ãã§ãããããã㧠ä¼èª¬ã®ããããã¨ãããã¾ããããè¨ã£ã¦ã¿ããã§ã ã¾ã å ã¯é·ãã§ãããããã°ãã¾ã thanks in advanceã§ã
ãã¼ã¸ã¾ã§ããããã ã
745 ï¼login:Penguin âXkB4aFXBWg ï¼2009/01/13(ç«) 16:53:25 ID:KdRVIBbl ã¨ããããlist1ãåæ¹ãªã¹ãã«ç½®ãæããããªããæ¤è¨¼ï¼æ¬å½ã«ããã§åãã確èªï¼ ãã¦ã¿ããã¨ã«ãªãã¾ãããããå¯è½ãªå ´åã¯ãrealpath(3)ã¯è§£æ¶ãã Alã¸ã®ç¢ºèªããããªããªãããã§ãã ã¾ããDavidã¨ã®ããã¨ãã¯ãå®ã¯Sergeãccããã¦ãããã¨ãå¤æãã(; ;) é¢ä¿è ã«è°è«ã®è¨¼è·¡ãlkmlã§ãããã¦ãããï¼Sergeãå«ãã¦ï¼é¢ä¿è ã«èãã¦ãã¾ãã ããããã¨ããã¯ããã£ã¦ããã¼ã¸ãç®æãã¾ãã 746 ï¼login:Penguin âXkB4aFXBWg ï¼2009/01/13(ç«) 18:43:30 ID:QtV6ZzdK ä¹ ãã¶ãã«Linux Weather Forecastãè¦ãã¦ã¿ãããtomoyoã®ã¨ãããæ´æ°ããã¦ãã¾ããã ttp://www.linuxfoundation.org/en/Linux_Weather_Forecast/security TOMOYO Linux TOMOYO Linux is a mandatory access control framework similar to AppArmor. Like AppArmor, it has been criticized for its use of pathnames and (to some) simplistic approach to security. Forecast: TOMOYO Linux has only recently surfaced on the wider mailing lists; its reception has not been entirely friendly. This project's developers have some work to do if they are (1) to get past the same obstacles which have slowed AppArmor, and (2) show that their project is sufficiently different from AppArmor to merit inclusion as yet another security framework. ã¨ããã¾ã§ã¯ããããããã¾ã§ã¨åãã§ããããã®å¾ã« The merging of the pathname-based security module hooks for 2.6.29 has helped this cause significantly, though; a 2.6.30 or 2.6.31 merge is not entirely out of the question. ï¼ãããã2.6.29ã§pathname-basedç¨ã®ããã¯ã追å ãããã®ã§ç¶æ³ã¯å¤§å¹ ã«å¤ãã£ãã 2.6.30, 31ã§ã®ãã¼ã¸ã¯å ¨ãããå¾ãªããã¨ã§ã¯ãªããªã£ãï¼ ã追å ããã¦ãã¾ããå¤åæ¸ãã¦ããã®ã¯Jonathanã§ããã³ã£ããã§ãã 747 ï¼login:Penguin âXkB4aFXBWg ï¼2009/01/13(ç«) 18:51:15 ID:QtV6ZzdK >>745 >ããå¯è½ãªå ´åã¯ãrealpath(3)ã¯è§£æ¶ãã >Alã¸ã®ç¢ºèªããããªããªãããã§ãã ã«ã¤ãã¦ããããã¯éããã¨å çã«çªã£è¾¼ã¾ãã¾ãããprocã®selfã®ã¨ããã ãããªããªãã ãã§ãä¸ã®å 容ã¯ééã£ã¦ããããã§ãã ã§ããã®ãããã¯ä½åèãã¦ããããããã¦ãããããã¾ããã»ã»ã»ã ã¡ããã¨èª¬æãããã®ããªãã®ãæªããã§ããï¼ç¬ï¼ 748 ï¼login:Penguinï¼2009/01/13(ç«) 19:04:13 ID:acMdqThM james_morris: Security changes in the 2.6.28 kernel ttp://james-morris.livejournal.com/37583.html @ 2009-01-06 20:55:00 Also noteworthy is the merge of the pathname security hooks for LSM, which should pave the way for TOMOYO and AppArmor in 2.6.30, subject to the general patch submission review process. TOMOYO is only a couple of acks from approval, has been baking in -mm, and is pretty much self-contained. It may even appear in 2.6.29 if the merge window is open for features long enough. 749 ï¼login:Penguin âXkB4aFXBWg ï¼2009/01/13(ç«) 19:36:07 ID:QtV6ZzdK >>748 thanks :-) Jonathan Corbetæ°ãããæ¥ã®ããã°ãã ttp://linux-foundation.org/weblogs/lwf/2009/01/11/looking-forward-to-2629/ One small, quiet piece of code which went in was a new set of security module hooks which enable the addition of pathname-based mandatory access control mechanisms. This was an important prerequisite for security modules like AppArmor and TOMOYO Linux, which may finally be getting close to inclusion into the mainline. ããããã¦ãlsmããã¯è¿½å ã®ãå°ããªã³ã¼ããã®ä¾¡å¤ãæãã¾ãã 757 ï¼login:Penguin âXkB4aFXBWg ï¼2009/01/14(æ°´) 18:12:32 ID:w5+hnGvV ããã»ã©æ稿ãããã¨ããããï¼ãã¼ã¸ãããã¾ã§ã¯ :-ï¼list1ããã¾ããçè¿ä¿¡ã§ãã James Morris wrote: > > By ommiting pointer to previous element, the reader becomes read lock free, > > which is good thing for implementing "write once read many" list. > > This has a technical ack from Paul, but what about Linus' long-standing > objection to singly-linked lists in the kernel? I'm sure this has been > discussed re. your patches, but I can't find a reference. > OK, for reviewers' ease, I purged list1 for now. Next posting (#15) will use standard doubly linked list with rw_semaphore. Thanks. 758 ï¼login:Penguin âXkB4aFXBWg ï¼2009/01/14(æ°´) 18:17:14 ID:w5+hnGvV åãã/proc/selfããsad thingã®é¨åãæ³£ããã¾ãã;-) James Morris wrote: > > (3) /proc/PID/ is represented as /proc/self/ if PID equals current->tgid. > > This needs an ack from Al and/or Christoph. > It is a sad thing that I cannot use /proc/self/ (which is the only part where a pathname based access control can prevent current process from accessing other process's information), but I purged d_realpath() for now. Next posting (#15) will embed AppArmor's d_namespace_path()-like function into TOMOYO's code. 対å¿ã®æ¹éã決ã¾ã£ã¦ãã3人ãç´å¾ã§ãããããªææ¡ãèããã®ã大å¤ã§ãã;-) Sergeã«ã¤ãã¦ã¯ã¡ã¼ã«ã§ããã¨ããã¦ãã¦ãè¿äºå¾ ã¡ã§ãããStephenãªã©ã ãã§ãã¯ãã¦ããã®ã§ããããããããã¦ãããªãããªã¨ (^O^; 761 ï¼login:Penguinï¼2009/01/14(æ°´) 19:52:07 ID:5NKh0/Wc çµå±æ£è¦è¡¨ç¾é¢æ°ç¾¤ã¯ã©ããã¡ãããã ã 764 ï¼login:Penguin âXkB4aFXBWg ï¼2009/01/15(æ¨) 12:01:27 ID:cWUoCFDQ >>761 >çµå±æ£è¦è¡¨ç¾é¢æ°ç¾¤ã¯ã©ããã¡ãããã ã >>687 ã®ãã¨ã§ããï¼ æ¨æ¥ã®ä¸ã§ã®è©±ãåãã§ã¯ãæ¢åãªã¹ãã®å©ç¨ãselfãããããããã®ä»ã« descriptionã¨commentã®è¦ç´ããè¡ããã¨ã決ãã¾ããããLCAãããã ãããã®åæ çµæã#15ã¨ãã¦æ稿ããã®ã¯1ææ«ã«ãªãããã§ãã 2.6.29ã®ãã¼ã¸ã¦ã£ã³ãã¦ãéããLKMLã§æ°ãã«stackableã®è°è«ãå§ã¾ããªã©ã å ´ã¯åãã¦ãã¾ããä½æ¦ã¨ãã¦ã¯ ã¨ããããLKMLææã«å¯¾å¿ãããã®ãæ©ã æ稿ããã®ãåªå ã¨ããèãæ¹ã§ãã 765 ï¼login:Penguin âXkB4aFXBWg ï¼2009/01/15(æ¨) 12:09:54 ID:cWUoCFDQ >>761 ãã¼ãµã«ã¤ãã¦èªåã®èããæ¸ãã¾ããï¼ä»æ¥ã¯å çã¯ä½èª¿ä¸è¯ã§ãä¼ã¿ã§ãï¼ ãã«ã¼ãã«å ãã¼ãµã£ã¦ã©ããï¼ãã¨ããã³ã¡ã³ãã¯éå»ç¢ºãã«ããã¾ãããã 好ã¾ãããªãã®ã¯äºå®ã¨æãã¾ãã ãã ãtomoyoã«ã¤ãã¦ããã¼ãµãã¨å¼ã°ãã¦ããé¨åã¯ããã¹ããã®ã¾ã¾æåå ã¨ãã¦æ ¼ç´ãã¦ããã¨ããã®ãå®éã§ãæ±ç¨ã®æååæä½ã©ã¤ãã©ãªã§ã¯ãªãã ãããDBã«è¿ããã®ã¨æãã¾ã ï¼ããããã¼ãµã¨å¼ã¶ã¨è¨ãããã°ããããããã¾ãããï¼ã linux/lib以ä¸ã«ç½®ããããªãã®ã«ã¯é ãã§ãããtomoyoã¨ãã¦å¿ è¦ãªæ©è½ãèãã㨠ãã¤ããªå½¢å¼ã«å¤æãã¦ããããããã¨ã¯ãªãã¨ããã®ãå çã®èãã ã¨æãã¾ãã 769 ï¼login:Penguinï¼2009/01/16(é) 02:13:52 ID:T2fQPja9 >>765 ã«ã¼ãã«çã«ã¯ãã¼ãµã¼ä»¥å¤ã®ä½è ã§ããªããã ããã ãããæ¬å½ã«strcpy()ãã¦æ ¼ç´ãã¦ãã ããªãæå¥ã¯çµ¶å¯¾ããªãã¨æãã 771 ï¼login:Penguin âXkB4aFXBWg ï¼2009/01/16(é) 07:26:08 ID:1W9JShIi >>769 å¤åãæååã§æ ¼ç´ãã¦ããæç¹ã§ãã¼ãµãªãã ã¨æãã¾ãã(; ;) ã§ãtomoyoã®å ´åã¨ãããtomoyoã®ä½¿ãæ¹ã¯ã«ã¼ãã«å ã§ãã£ã¦ã 許容ãããç¯å²ã§ã¯ãªããã¨æãã¾ããéã«è¨ãã°ããã¤ããªã§ä¿åã㦠ã¤ã³ããã¯ã¹ãã¤ãã¦ãã誰ã«ã¨ã£ã¦ããããããã¨ã¯ãªãããã«æãã¾ãã 772 ï¼login:Penguinï¼2009/01/16(é) 21:21:00 ID:T2fQPja9 >>771 ãã¤ããªã§ä¿åããã®ã«æå³ããªãã¨ããã®ã¯ãã®ã¨ããã ã¨æãã ããã¯ã¬ãã¥ã¼ã¯ã¼ããããããã¨ãé¿ããã®ãNAKãããªãçºã«éè¦ãã¨ãã ååãã¯ããã¯ã®è©±ã ã¨ãæãã ã§ããã¡ã³ããã¼ãéå»ã®çµé¨ã¨ãã¦æååå¦çã¯ã¤ã¾ãããã°ããããã¡ãªã¼ãã¼ããã¼ã ç£ã¿ããããéå»ä½åº¦ãã»ãã¥ãªãã£å§åãããã£ã¦ãããªæããããçµé¨ãããã¡ãã㨠ããçç±ããªããããã ãã¨æã£ã¦ããã¨ããèæ¯ã¯ç解ããã¹ãã§ã ãã ã£ã¦åã¯ãããã ãããçãªèª¬å¾ã¯ç¸æã®å¿ã«é¿ããªãã ã®ã§ãäºåã«ä½æ¦èãã¦ãããã»ãããããã¨ã¯æãã ãã¨ãã°ããã¹åãã¼ã¹ã»ãã¥ãªãã£ã®ããã«ãã«ã³ãã¡ã¬ã³ã¹çãéãã¦ãã³ã³ã»ãããã ã¬ãã¥ã¼ãã¦ããã£ã¦ æ¿èªãåããã¨ããã®ãï¼ã¤ã®æã ãã誰ãã¨çµãã§å ±éã©ã¤ãã©ãªã« ãã¦ããããã ä½ãä»ã®æ段ã§ãããã£ãããä¸ãããã°ãããã ã¨ããèªèã æè©®ã³ã¹ã vs ãããã£ããè°è«ãªã®ã§ã ãããããã£ã¨è¡æ°ã縮ãã¦ãã»ãã®ã«ã¾ããã¦å ¥ãã¦ãã¾ãã¨ããå¯æãã¢ãªã¯ã¢ãªã ä»ã¯èª¬æãªããã³ã¼ãã¯ç®ç«ã¤ãå¿ ç¶æ§ãããåãããªãã®ï¼ç¹ã»ãããªã®ããããªã㨠æãã®ã§ããã 773 ï¼login:Penguinï¼2009/01/16(é) 21:27:21 ID:T2fQPja9 åã®ç解ã§ã¯ãTOMOYOã®ç¬èªè¨æ³ã®ã¡ãªãããã³ã³ã»ã³ãµã¹ãå¾ããã¦ããã¨ã¯ ãããããã¨æã£ã¦ãã®ãã å°ãªãã¨ãç¬èªè¨æ³ã¯ç¢ºå®ã«å ±æã³ã¼ããæ¸ãã¨ãããã¡ãªãããããããªã®ã§ã ãããä¸åãã¡ãªããããããã¨ã®èª¬æã¯å¿ è¦ã¨æãã 774 ï¼login:Penguinï¼2009/01/16(é) 21:29:30 ID:T2fQPja9 ããã¼ãµã¼ã ã£ããã絶対ã ããçãªéæ¿ãªäººã¯ä¸äººãããªãã¨ããèªèãªã®ã§ã è¦ã¯ãã¡ãªããï¼ãã¡ãªãã ã説å¾ã§ããããã§ãã©ã®è¦³ç¹ããæ»ããã®ããæ¦ç¥æ±ºãããããã¨
æ¦è¡ãã£ã¦ã®æ¦ç¥æ¦ç¥ãã£ã¦ã®æ¦è¡ãªã®ã ãã©ãTOMOYOã«ã¯æ¦ç¥ããªãã
777 ï¼login:Penguin âXkB4aFXBWg ï¼2009/01/16(é) 22:57:22 ID:1W9JShIi çç«å çã¨LiveCDã®ä¸ã®äººã¯æ¥é±au confã®ããã次ã«3åãæãã®ã¯1/26ã«ãªãã¾ããã æ»ã£ã¦ããã#15ã®æºåãä»ã®ä½æ¥ã§ãã°ãããã¾ãã¬ã¹ãã¤ããããªãããããã¾ããã ã³ã¼ãã®ä¿®æ£ã«ã¤ãã¦ã¯ããã¾ã§ãããã¦ããããã«æçµçã«ã¯çç«å çãå¤æãã¾ãã ãããããããããã ããææ¡ããæè¦ã¨åãã«ãªããªããã¨ãããããããã¾ãããã§ã ã§ããã ãç´å¾ãã¦ãæãããã«ãã£ã¦ããããããã¦è¯ãçµæãåºãã¦æ¬²ããã¨é¡ã£ã¦ãã¾ãã tomoyoã®ãã¨ãä¸çªç解ãã¦ããã®ã¯å çã ããå çãããªããã°tomoyoãåå¨ãã¦ããªãã®ã§ãã 対å¿ãã¦ããããªãã¦ããããã§ããã£ãæè¦ã¯3åã¨ãæ·±ãæè¬ãã¦ãã¾ãã æ°ã«ãã¦ãããããã¨ãæ¬å½ã«ããããæã£ã¦ãã¾ãã ã§ãµã 778 ï¼login:Penguin âXkB4aFXBWg ï¼2009/01/16(é) 23:40:42 ID:1W9JShIi >>777 ãã ï¼ï¿£ã ̄\ ãï¼ãã _ãããï¼¼ããã»ã»ã»ä½ãè¨ãããï¼ ï¼ä½ãã«777è¸ãã§ããï¼ ã|ããã ï¼ âï¼ï¼âï¼ããããããã ãã ã ã ____ .ã|ãï¼µãã ï¼__人__ï¼ãããããããã ããï¼ãã ã ãï¼¼ ã |ãããï¼µãï½ â´|ããããããã ãããï¼âã ã âãããï¼¼ .ã |ãï¼µãããããã}ããï¼¼ããã ããï¼ ï¼âï¼ãï¼âï¼ ãããï¼¼ ãã .ã ã½ããããã ã } ããã ï¼¼ã ã ã|ã ãï¼__人__ï¼ãããã ã |ãæ¸ãã¦ã¦èªåã§ãããããªãã£ããã ãã ã½ããããããããã ã ãï¼¼ãã ï¼¼ãã ï½ â´ ããããã_ï¼ ãã ããã/ããã ã.ãï¼¼ããããããï¼¼ã ããããããããããã ï¼¼ ããã|ãããã ï¼¼ ãï¼¼ãããã(âäºããã ãããããããã ã| ã ã |ãããã|ã½ãäºâ)ããããã ãï¼¼ããããããã ãï½ ã| 779 ï¼login:Penguin âXkB4aFXBWg ï¼2009/01/16(é) 23:46:12 ID:1W9JShIi ãã ã ã ____ ããããï¼ãã ã ãï¼¼ ãã ï¼ããâã ã â ï¼¼ ãï¼ ãã ,ï¼âï¼ãï¼âï¼ï½¤ï¼¼ ãããã ããã£ã¦ãã¡ãªãæ¬è½ ã|ã ãã ã ï¼__人__ï¼ã| ãï¼¼ãããã ï½ â´ãã ï¼ ,,.....ã¤.ã½ã½ã___ ã¼ã¼ãï¾-、. :ã ã| ã';ãï¼¼_____ ã.| ã½ãi ã ã |ããï¼¼/ï¾ï¼__)ï¼¼,| ãiã| ã ã ï¼ãã ã½. ãã | ã |ï½ ãããããããããã ã -â '´ ̄ ̄ï½ã½ï½¤ ãã ã ã ã ã ã ï¼ãï¼" ï½ã½ ã½ããï¼¼ ããããããããã//, '/ãããã ã½ï¾ ã、ãã½ãããããã ãããããããã ã {_{ãããã ï½ã½ï¾| ï½ â i| ãããããããã ï¾!å°ï½âããã â ä»ã|ãi|ããåç©ãï¼ ããããããã ã ã½|lâã、_,、_,ãââã|ï¾âãã ã ã ã ã /âã½__|ï¾ãã ã._ï¼ã ãj /âi !ãã ããããããï¼¼ /:::::|ãlï¼,、 __,ãã¤ã¡/ã /âãã ããããã ã /:::::/|ã|ãã¾:::|ä¸/::{ï¾ï½¤__⧠| ãããããããï½ã½< |ã|ããã¾â¨:::/ã¾:::彡'ã| åè«ã¯ã¨ãããæè¿ããã«å ¥ã浸ã£ã¦ãã¦ä»ã®ãã¨ãã§ãã¦ãªãã£ãã®ã§ï¼æ¬å½ï¼ã au confãçµããã¾ã§ãã°ããã²ããããã¾ãã 780 ï¼login:Penguinï¼2009/01/16(é) 23:59:28 ID:T2fQPja9 >>777 ãã¼ããã³ã¼ãã®ä¿®æ£ããããªããã«è°è«ãå°ãããªã£ã¦ããã®ã¯ãã¡ãã£ã¨æ®å¿µã ã©ãããéãã¦ãªãæ°ããããªãåãªãããæ¸ãã¨ããã®ãåºããã ã¾ããè«æã§ããã®ã§ãæåã«ã¢ãã¹ãã©ã¯ããæ¸ãã ãã¹åãã¼ã¹ã®ã»ãã¥ãªãã£ã¢ã¸ã¥ã¼ã«ã§ã¯ãã«ã¼ãã«ã«å¯¾ãã¦å¯¾è±¡ãªãã¸ã§ã¯ãã ãã¹åã§æå®ããã ãã®ãã¹åã¯ãã¡ã¤ã«ãã®ãã®ã®ãã¹ã§ããããç¾å®çã«ã¯ããã£ã¨æè»ãªæå®æ¹æ³ã å¿ è¦ã§ããã ï¼ããªãã®ã·ã¹ãã ã§/etc/以ä¸ã«ä½åãã¡ã¤ã«ãããããèãã¦ã¿ãããï¼ã¤ï¼ã¤æå®ãã æ°ã¯ããã«å¤±ããã ããï¼ ãããæã ã¯æè»ã§ãã¯ãã«ã§ãããã¤ã 誤解ãã«ãããã¹åã®è¨æ³ãå¿ è¦ã§ããã ã»ã»ã»ãªã©ã®ããã«æ¸ãã¦ãregularãªexpression ã¯å¿ é ãªã®ã¯ããããã ããã ã©ãããexpressionãããããè°è«ãããããçãªåºã ãã«ããã ãã§ã次ã«é¸æè¢ãï¼ã¤ä¸¦ã¹ã ï¼ï¼ shell glob style expression ï¼ï¼ POSIX regular expression (UNIX style regular expression) ï¼ï¼ ç¬èªè¨æ³ ï¼ ï¼ï¼ã¨ï¼ï¼ãæ®éã®äººãæåã«æãã¤ãé¸æè¢ãªã®ã§å¿ ãã®ãããããã§ãã¨ã§ã ï¼ï¼ã¨ï¼ãè«ç ´ãã¦ï¼ã®TOMOYOç¬èªè¨æ³ãµã¤ã³ã¼ã ï¼ ã¨ããçµè«ã«èªå°ããäºãç®çã«ãã AppArmerã¯ï¼ï¼ï¼ãé¸æãã¦ãããä¸è¦ããã¯ããé¸æè¢ã«è¦ããããããããã«ã¯ é大ãªè¦è½ã¨ããããã POSIX regular expressionã®ã¡ã¿ãã£ã©ã¯ã¿ã®å¤ãã¯ãã¡ã¤ã«ã·ã¹ãã ã§ä½¿ç¨å¯è½ãª æåã§ãããã¨ã³ãã¦ã¼ã¶ã¯ééã£ãæ£è¦è¡¨ç¾ãæ¸ããããã ã¾ããlinuxã§ã¯ãç¿æ £ã¨ãã¦ãè±æ°å以å¤ã®ãã¡ã¤ã«ãã»ã¨ãã©åå¨ããªãããã ééã£ãæ£è¦è¡¨ç¾ã§ãåãã¦ãã¾ãã®ãåé¡ã ã ããã¯æ»æè ãç¹æ®ãªãã¡ã¤ã«åã®ãã¡ã¤ã«ãä½æããã¨ãã«ãåãã¦ééããé²è¦ããäºã« ãªã ï¼ããã§å ·ä½ä¾ãï¼ï¼ï¼åããã ï¼ã¤ã¥ãï¼ 781 ï¼login:Penguinï¼2009/01/17(å) 00:05:30 ID:BLqmOvB5 ããã¯èª°ãæªãã®ã ãããï¼ TOMOYOã®ãã°ãï¼æããã«éããTOMOYOã¯æå®ãããéãã«åãã¦ããã ã§ã¯ãã¨ã³ãã¦ã¼ã¶ãï¼AppArmeré¢ä¿è ã¯Yesã¨çããã ããã ãããããæã ã¯ãããæããªãã ã¦ã¼ã¶ãæ£ãã使ããªãã»ãã¥ãªãã£ã¢ã¸ã¥ã¼ã«ãªã©ããªãã®ã»ãã¥ãªãã£çãªä¾¡å¤ã ããã ããã æã ã«ã¯ã誤解ãã«ãããæçãªã·ã³ã¿ãã¯ã¹ããã£ããPOSX regular expression㨠åçã«ãã¯ãã«ãªè¨æ³ãå¿ è¦ã ã ãã£ã¦ãæã ã¯ä»¥ä¸ã®è¨æ³ãææ¡ãã ï¼ããã§TOMOYOè¨æ³ã®ç´¹ä»ã«ãã¤ã ï¼ãã¶ãããã¾ã®TOMOYOè¨æ³ã¯ã¡ã¿ãã£ã©ã¯ã¿ããã¡ãã£ã¨å¤ãããã®ã§è«æã®é½åä¸ ï¼ããã¡ãã£ã¨ãã¤ã¨ããããã¦ãã㨠ï¼ã¹ãã¼ãªã¼ãéããããããã ãã®è¨æ³ã¯ã·ã³ãã«ã§ãã¯ãã«ã§ãããã¦ãã»ãã¥ã¢ãã ã ã¨æ¸ãã¦è«æããããã ç¸æã¯TOMOYOã®èè ã§ã¯ãªããã»ãã¥ãªãã£ã®èè ãªã®ã§ãã¢ããã¼ãã¯ããªãã ãã»ãã¥ã¢ãã¨ããåèªãå«ããã ããã¸ã§ã¯ãã§äºç®ãç²å¾ããããã«ã¨ãã人ã¨è©±ãããã¨ãã¯ãTOMOYOãåããã°ããªãã® çåã¯è§£æ±ºãã¾ããã¨ã¯ãããã«ãç²ã ã¨ãéã®è©±ãããã¨æããããã¨åãã ç¸æã«ãã£ã¦ãä¼è©±ã®ãã¼ãã¤ã³ããå¤ããã 782 ï¼login:Penguinï¼2009/01/17(å) 00:11:06 ID:BLqmOvB5 以ä¸ãåãããããã£ã¹ã¯ãªãã·ã§ã³ãæ¸ããªããã¨ããä»®å®ã§ãæ¸ãã¦ã¿ããã©ã TOMOYOã«ã¼ã«ã ãããã¨ããåèªã¯ä½¿ããã«ãã»ãã¥ãªãã£ãèãã¦ãã£ããã ä»ã®è¨æ³ã«ãªã£ã¡ãã£ããã¨ããã¹ãã¼ãªã¼ãä½ãããã¨ããã®ã¯åãã£ã¦ ããããã¨æãã ãããã£ã¦ãçç±ãæ¸ãã¦ããã¨ã¬ãã¥ã¢ã¼ã¯ "It's no sense!!" ã¨ã¯ããã«ããã®ã§ã æ¿èªãããã建è¨çãªä»£æ¿æ¡ãåºããã®äºæã«ç²¾ç¥çã«è¿½ãè¾¼ã¾ããã ã»ã»ã»ã»ãµã ãã¬ãã¥ã¼ã¯ã¼ã®åããã£ã¦ããã ããï¼ ãã¡ãããæ¬å½ã«ã建è¨çãªä»£æ¿æ¡ãã§ã¦ãã¡ãã£ãããã¡ããã¨å¯¾å¿ããªãã¨ãã¡ã§ããã ããåºè·ãã¡ãã£ãããå¤ããããã¼ã¼ãã¨ãã¬ãã¥ã¼æå¦ãã¨æããã°ããã®çºè¨ã㦠åçºããã£ãAppArverã®äºã®èã«ãªããªãããã«ã 784 ï¼login:Penguinï¼2009/01/17(å) 00:27:44 ID:BLqmOvB5 ã§ã話ããã©ãã¨ãããã¯ç¸æã«ãã¡ãã®æèããã¬ã¼ã¹ã§ããããã«ãã¦ã ãããã£ãããä¸ããä½æ¦ãã æåã«å®è£ ã¤ãã£ã¦ãå£èª¬ãæ¹ãèããããããå£èª¬ãæ¹ãèããå¾ã§ã ããã«ãããã¦å®è£ ä¿®æ£ããã»ãããèããå¹ ããåºãã¨ããã¨ãåºæ¥ããã ããã ä»ã«ãããããä½æ¦ã¯ããã¨æããã©ããã®ã¼ã¯å£èª¬ãã®ãã女ãå£èª¬ãã®ãã ãããã¦éãã¯ãªãã¦ãç¸æã«ä¼ããã¦ã¢ããã¼ãå¤ããã®ãã¢ã ã¨æãã®ã§ãã ãã¶ããTOMOYOã®æ¹ã ã¯åãããã»ãã¥ãªãã£ã«æ°å詳ããã®ã§ããã£ã¨ããå£èª¬ãæå¥ã èããããã¯ãã
è«æãæ¸ãããã«æ¸ããç´ æµã ã
å£èª¬ãæ¹æ³ãç¸æã«åããã¦ã¢ããã¼ããå¤ããã
783 ï¼ãã ãããããï¼2009/01/17(å) 00:24:03 ID:Z3OQs+LA ããï¾ï¾ï¾ï½ï½±ï½° ãã ãããããâ§ï¼¿â§ ãã _ãâ\_ãã ãã < ï¼ï½Ð´>ãã¢ã¤ã´ï¼ï¼ã¢ã¤ã´ã©ã©ï¼ ãï¼ ãâ§â§ãã ãï¾ï¾ï½¼ï½¯Î£ï¼=====ï¼ (ï¼¼ãï¼ ä¸ï¼¼ã彡ãããã ( â)ã£)。'。ï¾_ï½¥ï¾ ã< ï¼ãï½ã´ .ï¼ãï¼ï¿£ï¿£ï¿£'ã ̄ ̄ï¼ï¼¼ ããï¼¼ããâ ï¼ã ̄ ̄ ̄ ̄| | ̄ ̄ ̄ ̄ ããï¼ããããï¼¼ãããããã| | ããã ̄ ̄ ̄\)ãã ã .ï¼ãï¼¼ TOMOYOã®ããã«ï¾ ï¾ï½²ï½·ï½±ï¾ï¼ ããã§ãã 785 ï¼login:Penguinï¼2009/01/17(å) 00:28:31 ID:BLqmOvB5 >>783 ããããéãã¼wwwwww
TOMOYO Linuxã«å¦ã¶èª¬å¾è¡ããã®ï¼
ãªãããã¢ã¹ãã¼ã¢ã¼ãã§åãã¦ãã¾ã£ãã®ã§ãç¶ããã
æè¡çãªè°è«ã¯ã»ã¼åæã¨ããæããã
ããã¦15åç®ã®LKMLã¸ã®æ稿ã¨ããã¡ãã»ã¼ã¸ã
822 ï¼login:Penguin âXkB4aFXBWg ï¼2009/02/05(æ¨) 23:52:49 ID:EiMYLrjN æ¨æ¥ã#14ã§æªè§£æ±ºã«ãªã£ã¦ããSergeã®åãããã«çããã¨ããã ç´å¾ãã¦ããããã©ããã¯ãããã¾ããããæ°ããªã¤ã£ãã¿ã¯ ããã¾ããã§ããã å ´ã®ç©ºæ°ãå¤ããã¨ç¶æ³ãé£ãããªãå¯è½æ§ããããã¾ãã¿ã¤ãã³ã°ã é ããã¨2.6.30ã®ãã¼ã¸ã¦ã£ã³ãã¦ã«éã«åããªãã®ã§ã ããã§ã®è°è«ãéä¸ã§ãããæ¬æ¥ä¸ã®äººä¼è°ãè¡ãã#15ãæ稿ãã¾ããã descriptionã®è©³ç´°åãªã©ãæä½éã®å¯¾å¿ã¯ã§ãã¦ãã¾ãã ä»åº¦ããï¼ (^O^)/ ãªã¼
ãããããã
825 ï¼login:Penguinï¼2009/02/07(å) 08:17:48 ID:wkPuQF66 ãã ï¼ï¿£ï¿£ï¼¼ ãï¼ãã _ãããï¼¼ããã»ã»ã»ã©ãããåºã¤ãããããã ã ã|ããã ï¼ âï¼ï¼âï¼ããããããã ãã ã ã ____ .ã|ãï¼µãã ï¼__人__ï¼ãããããããã ããï¼ãã ã ãï¼¼ ãããã¦ãæè¦ãåºã¤ããã ã |ãããï¼µãï½ â´|ããããããã ãããï¼âã ã âãããï¼¼ ããã¨ãããã¨ã§ .ã |ãï¼µãããããã}ããï¼¼ããã ããï¼ ï¼âï¼ãï¼âï¼ ãããï¼¼ããã¸ã§ã¼ã ãºããã¼ã¸ããã®ã .ã ã½ããããã ã } ããã ï¼¼ã ã ã|ã ãï¼__人__ï¼ããã ã ã|ãã ãã ã½ããããããããã ã ãï¼¼ãã ï¼¼ãã ï½ â´ ããããã_ï¼ ãã ããã/ããã ã.ãï¼¼ããããããï¼¼ã ããããããããããã ï¼¼ ããã|ãããã ï¼¼ ãï¼¼ãããã(âäºããã ãããããããã ã| ã ã |ãããã|ã½ãäºâ)ããããã ãï¼¼ããããããã ãï½ ã|
ããã¦Jamesã®ããªã¼ã«
831 ï¼login:Penguin âXkB4aFXBWg ï¼2009/02/12(æ¨) 14:39:38 ID:arb85fbR Jamesã®ããªã¼ã«ã¯ããã¾ããã 832 ï¼login:Penguinï¼2009/02/12(æ¨) 14:49:50 ID:ZU9msm4p ããããªã ttp://git.kernel.org/?p=linux/kernel/git/jmorris/security-testing-2.6.git;a=summary ããã£ã¨ããã 833 ï¼login:Penguin âXkB4aFXBWg ï¼2009/02/12(æ¨) 14:52:06 ID:arb85fbR ãããã¨ãï¼ ã§ããæ£ç´ãä»ãã®æ®µéã§ã©ãã ãåãã§ããã®ãããããªãã®ã§å°ã£ã¦ãã¾ãï¼ç¬ï¼ 834 ï¼login:Penguin âXkB4aFXBWg ï¼2009/02/12(æ¨) 15:04:21 ID:arb85fbR ã ãã ã ã ãã ãããããããªã£ã¦ããã(T_T) 835 ï¼login:Penguin âXkB4aFXBWg ï¼2009/02/12(æ¨) 15:13:36 ID:arb85fbR ttp://lists.sourceforge.jp/mailman/archives/jsosug-users/2009-February/000068.html 836 ï¼login:Penguin âXkB4aFXBWg ï¼2009/02/12(æ¨) 15:35:18 ID:arb85fbR >>833 >ã§ããæ£ç´ãä»ãã®æ®µéã§ã©ãã ãåãã§ããã®ãããããªãã®ã§å°ã£ã¦ãã¾ãï¼ç¬ï¼ æ¬æ ¼çã«æ¥ãã¨ã¢ã¬ã ãã©ãå°ãããããªãæ¥ã¦ãããããããªããï¼ï¼éãï¼ï¼
ããã¦Linus' treeã«ãã¼ã¸ãããã
992 ï¼login:Penguinï¼2009/04/08(æ°´) 23:08:09 ID:tDtF8ZyH ãããã¨ããããã¾ããããã¾ã§ããµãããã㨠確ãã«è¦å´ãããããæ©ãã ãããã¾ãããã ãã以ä¸ã«éã«ããã¾ãã¦ãããã ç´æ¥éæ¥ãããããªäººã«å©ããããã¨æãã¾ãã ããããå ¨ã¦ãç¡é§ã«ããªãããã«ãä»ã¾ã§ä»¥ä¸ã« ããã°ãã¾ãã
æå¾ã¾ã§èªãã§ããã¦ãããã¨ãã
å¿åã¬ãã¥ã¢ã¼ãææãã¦ãããã¨ã¯ãã©ããã¨ã£ã¦ãã交æ¸ãã¨ã®ã¤ããã ãLinuxã³ãã¥ããã£ç¹æã®ãã¨ã¨ãããããã対人é¢ä¿ã«ããã¦ãç¸æã¨å¦¥åç¹ãè¦ã¤ããã¨ãããã¨ã«é¢ããæ®éçãªæ¹æ³è«ãTOMOYO Linuxã¨ããäºæ¡ãä¾ã«æåä¸å¯§ã«èª¬æãã¦ããã交æ¸ãã¨ã®ãããã§ãã·ã§ãã«ã¨ããå¾ãããå³æ¹ãTOMOYO Linuxã¯ã¯ããããå¾ãããã§ããããªã¼ãã³ã½ã¼ã¹ããã¸ã§ã¯ãã§ãªããã°ããã®ãããªããã»ã¹ã第ä¸è ã§ããæã ã¯ããããç¥ãäºãã§ããªãã£ãããã®ï¼chã®ã¹ã¬ã®éå»ãã°ãèªããã¨ãåºæ¥ãæéãè¶ãã¦çä¼¼ä½é¨ã§ããã¨ããã®ã¯ããªã¼ãã³ã½ã¼ã¹ããã¸ã§ã¯ããªãã§ã¯ã§ããã
æ¨æ¥ã®TOMOYO Linuxã®åå¼·ä¼ã®å°å´ããã®ãã¬ã¼ã³ã§ç´¹ä»ããã£ãã®ã§ãï¼chã®éå»ãã°ãèªãã§ã¿ããæ³åãè¶ããããã¨ããããã«ã¯ãã£ããå°å´ãããã¯ããã¨ããTOMOYOã®å¤ã®äººã®ååãªãã§ã¯æ±ºãã¦ã¡ã¤ã³ã©ã¤ã³åã¯éæã§ããªãã£ãã®ã§ã¯ãªãã ããããã¤ããã¼ã·ã§ã³ã¯ä¼ç¤¾ã®å¤ã§èµ·ãããInnovation Happens Elsewhere (IHE)ã§ããã
Linuxã¯ã³ãã¥ããã£ãä½ã£ã¦ãã¦ãããã¯èª°ãä¸ã¤ã®ä¼æ¥ã®ãã®ã§ã¯ãªãã¨ãããã¨ãæ¹ãã¦å®æãããLinuxã¯ã³ãã¥ããã£ã®ãã®ã ãããã¦åç°ãããã¡ã¯ããããæ·±ãç解ããã
ããã§ã¨ãTOMOYO Linuxããããã¨ãTOMOYO Linuxã