All of lore.kernel.org
 help / color / mirror / Atom feed
* X windows with i810 chip
@ 2001-12-02 15:51 Justin Smith
  2001-12-02 22:21 ` Russell Coker
  2001-12-03 15:13 ` Stephen Smalley
  0 siblings, 2 replies; 6+ messages in thread
From: Justin Smith @ 2001-12-02 15:51 UTC (permalink / raw)
  To: selinux

X windows presents special problems with this (unfortunately common)
graphics chip. Even with all of the standard allows declarations for X
windows (and a few extras), I get the following:



avc:  denied  { read } for  pid=1215 exe=/usr/X11R6/bin/XFree86
path=/dev/mem dev=03:01 ino=25224
   scontext=jsmith:user_r:user_t
   tcontext=system_u:object_r:memory_device_t
   tclass=chr_file

avc:  denied  { read write } for  pid=1215 exe=/usr/X11R6/bin/XFree86
path=/dev/mem dev=03:01 ino=25224
   scontext=jsmith:user_r:user_t
   tcontext=system_u:object_r:memory_device_t
   tclass=chr_file
Linux agpgart interface v0.99 (c) Jeff Hartmann
agpgart: Maximum main memory to use for agp memory: 261M
agpgart: Detected an Intel i810 E Chipset.
agpgart: detected 4MB dedicated video ram.
agpgart: AGP aperture is 64M @ 0xf8000000

avc:  denied  { read write } for  pid=1215 exe=/usr/X11R6/bin/XFree86
path=/dev/mem dev=03:01 ino=25224
   scontext=jsmith:user_r:user_t
   tcontext=system_u:object_r:memory_device_t
   tclass=chr_file



I have been unable to enable this access (perhaps there's a 'neverallow'
coded for it). Any suggestions would be appreciated! (I really need  X
windows --- to the extent that I would have to discontinue using SELinux
if it prohibits it). 

Is there a way to allow memory access for a RESTRICTED range of
addresses (if so, a hacker would at most be able to display pictures on
the screen)?  (Maybe this would require assigning types to PARTS of a
device, ranges of bytes).
-- 


--
You have received this message because you are subscribed to the selinux list.
If you no longer wish to subscribe, send mail to majordomo@tycho.nsa.gov with
the words "unsubscribe selinux" without quotes as the message.

^ permalink raw reply	[flat|nested] 6+ messages in thread

end of thread, other threads:[~2001-12-03 20:22 UTC | newest]

Thread overview: 6+ messages (download: mbox.gz follow: Atom feed
-- links below jump to the message on this page --
2001-12-02 15:51 X windows with i810 chip Justin Smith
2001-12-02 22:21 ` Russell Coker
2001-12-03 15:13 ` Stephen Smalley
2001-12-03 20:05   ` Justin Smith
2001-12-03 20:18     ` Stephen Smalley
2001-12-03 20:22     ` Stephen Smalley

This is an external index of several public inboxes,
see mirroring instructions on how to clone and mirror
all data and code used by this external index.