All of lore.kernel.org
 help / color / mirror / Atom feed
From: Lorenzo Hernandez Garcia-Hierro <lorenzohgh@gmail.com>
To: Erich Schubert <erich@debian.org>
Cc: Stephen Smalley <sds@tycho.nsa.gov>,
	Manoj Srivastava <manoj.srivastava@stdc.com>,
	Russell Coker <russell@coker.com.au>,
	SELinux@tycho.nsa.gov
Subject: Re: Threaded applications and "execmem" privilege
Date: Mon, 28 Nov 2005 16:04:44 +0000	[thread overview]
Message-ID: <1133193884.13305.26.camel@localhost> (raw)
In-Reply-To: <1133191110.5276.17.camel@wintermute.xmldesign.de>

[-- Attachment #1: Type: text/plain, Size: 1486 bytes --]

El lun, 28-11-2005 a las 16:18 +0100, Erich Schubert escribió:
> Okay, that probably means that most apps (maybe not java and x.org, but
> I don't have these on my selinux boxes anyway) should work just fine.
> And others probably too, since IIRC i386 doesn't enforce that anyway...
> But I'll switch to the patch you posted.

In IA32 PROT_READ implies PROT_EXEC, but "separation" can be enforced:
 http://pearls.tuxedo-es.org/papers/linuxsec-lsm2005/img61.jpg
 http://pearls.tuxedo-es.org/papers/linuxsec-lsm2005/img50.jpg

> Some more information on the issue:
> http://wiki.debian-hardened.org/SSP/ProPolice_Implementations

Please note that information is obsoleted (Hardened Debian used libssp
for ProPolice implementation, although SSP got merged into gcc-4.1
later). Take it as an experiment, and a reliable way of introducing
changes in the SSP code without recompiling everything but just libssp.

Some people are switching to Gentoo (Hardened) due to the problems
caused by some changes introduced in Debian's libc. Some vserver and
grsec users. What's the status now? Is it going to be worked out?

BTW, I would like to help out with anything regarding SELinux deployment
in Debian. I'm trying to work out stuff for Ubuntu Linux, but if it gets
into Debian first, then Ubuntu guys will sync, avoiding efforts
duplication.

Cheers,
-- 
Lorenzo Hernández García-Hierro <lorenzo@gnu.org> 
[1024D/6F2B2DEC] & [2048g/9AE91A22][http://tuxedo-es.org]

[-- Attachment #2: Esta parte del mensaje está firmada digitalmente --]
[-- Type: application/pgp-signature, Size: 198 bytes --]

      parent reply	other threads:[~2005-11-28 16:04 UTC|newest]

Thread overview: 6+ messages / expand[flat|nested]  mbox.gz  Atom feed  top
2005-11-20 16:35 Threaded applications and "execmem" privilege Erich Schubert
2005-11-22 15:17 ` Erich Schubert
2005-11-28 14:31   ` Stephen Smalley
2005-11-28 15:18     ` Erich Schubert
2005-11-28 15:36       ` Stephen Smalley
2005-11-28 16:04       ` Lorenzo Hernandez Garcia-Hierro [this message]

Reply instructions:

You may reply publicly to this message via plain-text email
using any one of the following methods:

* Save the following mbox file, import it into your mail client,
  and reply-to-all from there: mbox

  Avoid top-posting and favor interleaved quoting:
  https://en.wikipedia.org/wiki/Posting_style#Interleaved_style

* Reply using the --to, --cc, and --in-reply-to
  switches of git-send-email(1):

  git send-email \
    --in-reply-to=1133193884.13305.26.camel@localhost \
    --to=lorenzohgh@gmail.com \
    --cc=SELinux@tycho.nsa.gov \
    --cc=erich@debian.org \
    --cc=lorenzo@gnu.org \
    --cc=manoj.srivastava@stdc.com \
    --cc=russell@coker.com.au \
    --cc=sds@tycho.nsa.gov \
    /path/to/YOUR_REPLY

  https://kernel.org/pub/software/scm/git/docs/git-send-email.html

* If your mail client supports setting the In-Reply-To header
  via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line before the message body.
This is an external index of several public inboxes,
see mirroring instructions on how to clone and mirror
all data and code used by this external index.