All of lore.kernel.org
 help / color / mirror / Atom feed
From: Steve Greenland <steveg@moregruel.net>
To: SE-Linux <selinux@tycho.nsa.gov>,
	193644@bugs.debian.org, Stephen Smalley <sds@epoch.ncsc.mil>
Subject: Re: Bug#193644: http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=193644 (cron upstream patch)
Date: Wed, 19 May 2004 16:54:09 -0500	[thread overview]
Message-ID: <20040519215409.GA7459@moregruel.net> (raw)
In-Reply-To: <20040519200057.GD24597@lkcl.net>

On 19-May-04, 15:00 (CDT), Luke Kenneth Casson Leighton <lkcl@lkcl.net> wrote: 
> 
>  ... therefore, i take it that you mean that the letters "system_u"
>  _could_ be used as a username, whereas "*" is an invalid character
>  which, _if_ used in /etc/passwd, would cause a login error.

Yes.

>  and i take it that _that_ is why you object to its use, yes?

No. How many times do I have to say this? It's the WRONG FSCKING FIELD.
The field the SE linux people are so obsessed with changing is NOT
THE USERNAME field. The username field is available. Using it for
controlling the SE context would do the right thing, right? For the
real user crontabs, it would have the real username, even for root. For
the system crontabs, under /etc, it could be system_u. Then calling
SE_get_security_context(username) (or whatever the function/terminology
is) would always be the right thing to do, yes?

(And no, it's not the same as the UID associated with a particular job.
That's yet another field.)

Steve

-- 
Steve Greenland
    The irony is that Bill Gates claims to be making a stable operating
    system and Linus Torvalds claims to be trying to take over the
    world.       -- seen on the net

--
This message was distributed to subscribers of the selinux mailing list.
If you no longer wish to subscribe, send mail to majordomo@tycho.nsa.gov with
the words "unsubscribe selinux" without quotes as the message.

  parent reply	other threads:[~2004-05-19 21:54 UTC|newest]

Thread overview: 17+ messages / expand[flat|nested]  mbox.gz  Atom feed  top
2004-05-19  9:14 http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=193644 (cron upstream patch) Luke Kenneth Casson Leighton
2004-05-19 13:30 ` Stephen Smalley
2004-05-19 14:02   ` Luke Kenneth Casson Leighton
2004-05-19 18:11     ` Bug#193644: " Steve Greenland
2004-05-19 20:00       ` Russell Coker
2004-05-20  6:14         ` Luke Kenneth Casson Leighton
2004-05-19 20:00       ` Luke Kenneth Casson Leighton
2004-05-19 21:02         ` Russell Coker
2004-05-19 21:54         ` Steve Greenland [this message]
2004-05-20  6:06           ` Luke Kenneth Casson Leighton
2004-05-20 12:06             ` Stephen Smalley
2004-05-20 12:23               ` Luke Kenneth Casson Leighton
2004-05-20 11:57           ` Stephen Smalley
2004-05-20 14:22             ` Luke Kenneth Casson Leighton
2004-05-20 15:48               ` Steve Greenland
2004-05-20 17:44                 ` Russell Coker
2004-05-20 18:55                 ` Luke Kenneth Casson Leighton

Reply instructions:

You may reply publicly to this message via plain-text email
using any one of the following methods:

* Save the following mbox file, import it into your mail client,
  and reply-to-all from there: mbox

  Avoid top-posting and favor interleaved quoting:
  https://en.wikipedia.org/wiki/Posting_style#Interleaved_style

* Reply using the --to, --cc, and --in-reply-to
  switches of git-send-email(1):

  git send-email \
    --in-reply-to=20040519215409.GA7459@moregruel.net \
    --to=steveg@moregruel.net \
    --cc=193644@bugs.debian.org \
    --cc=sds@epoch.ncsc.mil \
    --cc=selinux@tycho.nsa.gov \
    /path/to/YOUR_REPLY

  https://kernel.org/pub/software/scm/git/docs/git-send-email.html

* If your mail client supports setting the In-Reply-To header
  via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line before the message body.
This is an external index of several public inboxes,
see mirroring instructions on how to clone and mirror
all data and code used by this external index.