pcp
[Top] [All Lists]

Re: [pcp] pmcd security proposals

To: Nathan Scott <nathans@xxxxxxxxxx>
Subject: Re: [pcp] pmcd security proposals
From: Max Matveev <makc@xxxxxxxxx>
Date: Tue, 13 Mar 2012 22:44:59 +1100
Cc: "Frank Ch. Eigler" <fche@xxxxxxxxxx>, pcp@xxxxxxxxxxx
In-reply-to: <CAAp5ZgPJSmXwobDLf+m=pXSyNF5JCah3RVpD+by_tnnm_Vi8ug@xxxxxxxxxxxxxx>
References: <20120311235154.GA16874@xxxxxxxxxx> <CAAp5ZgPJSmXwobDLf+m=pXSyNF5JCah3RVpD+by_tnnm_Vi8ug@xxxxxxxxxxxxxx>
On Tue, 13 Mar 2012 09:44:37 +1100, Nathan Scott wrote:

 nathans> OTOH, agents like pmdammv, which allows arbitrary user
 nathans> processes to extend the set of values on the fly might be a
 nathans> better model (unless I'm missing something wrt your
 nathans> requirements here), where there is a strict interface
 nathans> between instrumented code and the agent, and the agent just
 nathans> interprets the data from the client in a read-only fashion.

pmdammv is not open to all either - you need to be able to create a
file in a directory and the directory can be restricted.

 nathans> It would be kind of handy to keep all permissions
 nathans> information in the one place, now that I think about it, so
 nathans> perhaps this should not be visible to the agents after all.

You will have to do it or agents with dynamic namespace will not work.

max

<Prev in Thread] Current Thread [Next in Thread>