All of lore.kernel.org
 help / color / mirror / Atom feed
* RE: Making OPIE/QTOPIA aware of SELinux
@ 2003-02-20 19:42 CNGUYEN
  2003-02-21  9:33 ` Tom
  2003-02-21 14:57 ` Lamont R. Peterson
  0 siblings, 2 replies; 7+ messages in thread
From: CNGUYEN @ 2003-02-20 19:42 UTC (permalink / raw)
  To: 'Russell Coker', 'Stephen D. Smalley',
	'selinux@tycho.nsa.gov'

Applications <----
----              |
OPIE/QTOPIA  <---------|
---                    |
SELinux                |
---                    | 
Device Drivers <-------|

-----Original Message-----
From: Russell Coker [mailto:russell@coker.com.au]
Sent: Thursday, February 20, 2003 11:36 AM
To: CNGUYEN; 'Stephen D. Smalley'; 'selinux@tycho.nsa.gov'
Subject: Re: Making OPIE/QTOPIA aware of SELinux


On Thu, 20 Feb 2003 17:42, CNGUYEN wrote:
> Any thoughts on how to make the GUI environment (OPIE or QTOPIA) aware of
> SELinux so that "bypassing" SELinux is prevented?

What exactly do you mean by "bypassing SE Linux" and in what ways do you
think 
it should be made aware of SE Linux?

I'm working on Familiar right now but my work is just starting...

-- 
http://www.coker.com.au/selinux/   My NSA Security Enhanced Linux packages
http://www.coker.com.au/bonnie++/  Bonnie++ hard drive benchmark
http://www.coker.com.au/postal/    Postal SMTP/POP benchmark
http://www.coker.com.au/~russell/  My home page

--
This message was distributed to subscribers of the selinux mailing list.
If you no longer wish to subscribe, send mail to majordomo@tycho.nsa.gov with
the words "unsubscribe selinux" without quotes as the message.

^ permalink raw reply	[flat|nested] 7+ messages in thread
* RE: Making OPIE/QTOPIA aware of SELinux
@ 2003-02-21 15:05 CNGUYEN
  0 siblings, 0 replies; 7+ messages in thread
From: CNGUYEN @ 2003-02-21 15:05 UTC (permalink / raw)
  To: 'lrp@xmission.com', 'Russell Coker',
	'Stephen D. Smalley', 'selinux@tycho.nsa.gov',
	'tom@lemuria.org'
  Cc: Chieu Nguyen (E-mail), David Gathright (E-mail)

Thank you for your advices, we will take these into consideration as we
investigate further into the QTOPIA/OPIE SDKs.

-----Original Message-----
From: Lamont R. Peterson [mailto:lrp@xmission.com]
Sent: Friday, February 21, 2003 6:58 AM
To: CNGUYEN; 'Russell Coker'; 'Stephen D. Smalley';
'selinux@tycho.nsa.gov'
Subject: Re: Making OPIE/QTOPIA aware of SELinux


On Thursday 20 February 2003 12:42 pm, CNGUYEN wrote:
> Applications <----
> ----              |
> OPIE/QTOPIA  <---------|
> ---                    |
> SELinux                |
> ---                    |
> Device Drivers <-------|

If I understand the architecture of the kernel (and particularly, how
SELinux 
affects the kernel) then I would have to say that your diagram is incorrect.

SELinux does not sit on top of the kernel; it "IS" the kernel.

Qtopia (I don't know OPIE) does not bypass the kernel in order to talk to 
devices directly.  There is nothing (other than compiling SELinux into your 
"embedded" kernel) that needs be done for Qtopia to run securely.

However, if I were to do this, I would write some Qtopia apps to wrap around

SELinux specific tools such as spasswd, and would explore the "login" 
facility that Qtopia Desktop uses to communicate with Qtopia devices.
-- 
Sincerely,
Lamont R. Peterson <lrp@xmission.com>

--
This message was distributed to subscribers of the selinux mailing list.
If you no longer wish to subscribe, send mail to majordomo@tycho.nsa.gov with
the words "unsubscribe selinux" without quotes as the message.

^ permalink raw reply	[flat|nested] 7+ messages in thread
* Making OPIE/QTOPIA aware of SELinux
@ 2003-02-20 16:42 CNGUYEN
  2003-02-20 19:36 ` Russell Coker
  0 siblings, 1 reply; 7+ messages in thread
From: CNGUYEN @ 2003-02-20 16:42 UTC (permalink / raw)
  To: 'Stephen D. Smalley', 'selinux@tycho.nsa.gov'

Any thoughts on how to make the GUI environment (OPIE or QTOPIA) aware of
SELinux so that "bypassing" SELinux is prevented?

Chieu Nguyen
Mykotronx

--
This message was distributed to subscribers of the selinux mailing list.
If you no longer wish to subscribe, send mail to majordomo@tycho.nsa.gov
with
the words "unsubscribe selinux" without quotes as the message.


--
This message was distributed to subscribers of the selinux mailing list.
If you no longer wish to subscribe, send mail to majordomo@tycho.nsa.gov with
the words "unsubscribe selinux" without quotes as the message.

^ permalink raw reply	[flat|nested] 7+ messages in thread

end of thread, other threads:[~2003-02-21 15:13 UTC | newest]

Thread overview: 7+ messages (download: mbox.gz follow: Atom feed
-- links below jump to the message on this page --
2003-02-20 19:42 Making OPIE/QTOPIA aware of SELinux CNGUYEN
2003-02-21  9:33 ` Tom
2003-02-21 14:57 ` Lamont R. Peterson
2003-02-21 15:13   ` Russell Coker
  -- strict thread matches above, loose matches on Subject: below --
2003-02-21 15:05 CNGUYEN
2003-02-20 16:42 CNGUYEN
2003-02-20 19:36 ` Russell Coker

This is an external index of several public inboxes,
see mirroring instructions on how to clone and mirror
all data and code used by this external index.