From: "Christopher J. PeBenito" <cpebenito@tresys.com>
To: Daniel J Walsh <dwalsh@redhat.com>
Cc: SE Linux <selinux@tycho.nsa.gov>
Subject: Re: latest diff
Date: Tue, 17 Jan 2006 13:35:25 -0500 [thread overview]
Message-ID: <1137522925.29815.276.camel@sgc> (raw)
In-Reply-To: <43CC6D3C.1060307@redhat.com>
Merged, with a few notes:
On Mon, 2006-01-16 at 23:06 -0500, Daniel J Walsh wrote:
> Added wine policy to mimic java.
>
> Do we need one for mono? Or do we change java policy to
> unconfined_execmem policy?
It looks like the wine policy falls into this too, which is why I
dropped the wine for now. It does look like unconfined_execmem is the
right way to go. My idea is that it should be transparent as much as
possible, like shlib_t/textrel_shlib_t. So for example, the
unconfined_domtrans() would have the regular transition and a transition
to unconfined_execmem_t.
> Do you have a problem with my range_transition rules?
The auditd one is ok, but I still disagree with the ping one. I don't
understand why it matters for ping, especially since only files are
handled by MCS.
> +allow system_mail_t eventpollfs_t:file r_file_perms;
> I got bug reports on the above. I have no idea why.
I put it in, but it would be interesting to find out why.
> I still think running hostname policy for anything other than init and
> dhcpc is a bad idea.
Agreed.
> + domain_dontaudit_read_all_domains_state($1)
> was added to unconfined_t to eliminate AVC messages created by running
> top when logged in on a MCS machine. If you are running unconfined_t:s0
> and run top you will not be able to read all the processes running at
> s0-s0:c0.c255
This is merged too, but its probably useful to put it in an
ifdef(`enable_mcs', since its dontauditing MCS denials. Might one also
be needed for MLS?
> Do you have a problem with the MLS gen_user stuff?
Theres a few things I'm wrestling with.
1. Do we really want to do this (more identities) for the upstream
policy?
2. Do we want to enable secadm for strict in general or just MLS?
3. The user file already has a large amount ifdefs, which can be
confusing.
The last one isn't really specific to the patch, but its been on my
mind, but as I'm writing this I have an idea how it might be remedied.
--
Chris PeBenito
Tresys Technology, LLC
(410) 290-1411 x150
--
This message was distributed to subscribers of the selinux mailing list.
If you no longer wish to subscribe, send mail to majordomo@tycho.nsa.gov with
the words "unsubscribe selinux" without quotes as the message.
next prev parent reply other threads:[~2006-01-17 18:34 UTC|newest]
Thread overview: 19+ messages / expand[flat|nested] mbox.gz Atom feed top
2006-01-17 4:06 latest diff Daniel J Walsh
2006-01-17 18:35 ` Christopher J. PeBenito [this message]
-- strict thread matches above, loose matches on Subject: below --
2006-01-27 6:37 Latest diff Daniel J Walsh
2006-01-27 20:07 ` Christopher J. PeBenito
2006-01-28 21:17 ` Daniel J Walsh
2006-01-24 21:58 Latest Diff Daniel J Walsh
2006-01-25 18:41 ` Christopher J. PeBenito
2005-05-19 18:51 Daniel J Walsh
2005-05-19 21:36 ` Ivan Gyurdiev
2005-03-22 18:24 Latest diff Daniel J Walsh
2005-03-22 20:20 ` Daniel J Walsh
2005-03-23 18:25 ` James Carter
2005-03-19 6:53 latest diff Daniel J Walsh
2005-03-19 16:14 ` Christopher J. PeBenito
2005-03-19 16:36 ` Daniel J Walsh
2005-03-23 11:10 ` Thomas Bleher
2005-03-23 13:51 ` Stephen Smalley
2005-04-20 12:22 ` Russell Coker
2005-03-21 19:40 ` James Carter
Reply instructions:
You may reply publicly to this message via plain-text email
using any one of the following methods:
* Save the following mbox file, import it into your mail client,
and reply-to-all from there: mbox
Avoid top-posting and favor interleaved quoting:
https://en.wikipedia.org/wiki/Posting_style#Interleaved_style
* Reply using the --to, --cc, and --in-reply-to
switches of git-send-email(1):
git send-email \
--in-reply-to=1137522925.29815.276.camel@sgc \
--to=cpebenito@tresys.com \
--cc=dwalsh@redhat.com \
--cc=selinux@tycho.nsa.gov \
/path/to/YOUR_REPLY
https://kernel.org/pub/software/scm/git/docs/git-send-email.html
* If your mail client supports setting the In-Reply-To header
via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line
before the message body.
This is an external index of several public inboxes,
see mirroring instructions on how to clone and mirror
all data and code used by this external index.