All of lore.kernel.org
 help / color / mirror / Atom feed
From: Luke Kenneth Casson Leighton <lkcl@lkcl.net>
To: Valdis.Kletnieks@vt.edu
Cc: James Morris <jmorris@redhat.com>,
	Stephen Smalley <sds@epoch.ncsc.mil>,
	Joshua Brindle <method@gentoo.org>,
	SE-Linux <selinux@tycho.nsa.gov>
Subject: Re: temporary hack to use udev in selinux
Date: Thu, 29 Jul 2004 23:11:46 +0100	[thread overview]
Message-ID: <20040729221146.GO9950@lkcl.net> (raw)
In-Reply-To: <200407292059.i6TKxGFL019918@turing-police.cc.vt.edu>

usb-mount does this by using sudo.

it's a very clever program, but from a security perspective i ain't
entirely enamoured with the number of additions i've had to make
to fsadm.te, the number of extra permissions to mount_t and user_t
and i'm sure i've got something wrong, here.

however, that aside, usb-mount is at present only set up to
do usb hotplug devices.

perhaps it could be adapted to do scsi and ide drives, and consequently
cdroms too?

does hotplug "do" cdrom drives?

l.

p.s. anyone interested in the rather drastic hacks i've done for
usb-mount, let me know.

p.p.s. neither sg_map nor disktype are catered for in fsadm.te,
so i've had to add stuff for those.

On Thu, Jul 29, 2004 at 04:59:16PM -0400, Valdis.Kletnieks@vt.edu wrote:
> On Thu, 29 Jul 2004 13:06:15 EDT, James Morris said:
>  
> > This could be done by simply allowing context= to override any other 
> > behavior, right?
> 
> Well, with proper control over what roles/etc can use that mount option.
> (Think "/dev/cdrom auto-mounted as 'user' by a system daemon"...)



-- 
-- 
Information I post is with honesty, integrity, and the expectation that
you will take full responsibility if acting on the information contained,
and that, should you find it to be flawed or even mildly useful, you
will act with both honesty and integrity in return - and tell me.
--
<a href="http://lkcl.net">      lkcl.net      </a> <br />
<a href="mailto:lkcl@lkcl.net"> lkcl@lkcl.net </a> <br />


--
This message was distributed to subscribers of the selinux mailing list.
If you no longer wish to subscribe, send mail to majordomo@tycho.nsa.gov with
the words "unsubscribe selinux" without quotes as the message.

  reply	other threads:[~2004-07-29 22:00 UTC|newest]

Thread overview: 31+ messages / expand[flat|nested]  mbox.gz  Atom feed  top
2004-07-28 23:20 temporary hack to use udev in selinux Luke Kenneth Casson Leighton
2004-07-29  0:29 ` Joshua Brindle
2004-07-29  0:57   ` Luke Kenneth Casson Leighton
2004-07-29  1:35   ` Luke Kenneth Casson Leighton
2004-07-29  2:04     ` Luke Kenneth Casson Leighton
2004-07-29 12:47       ` Stephen Smalley
2004-07-29 14:20         ` Luke Kenneth Casson Leighton
2004-07-29 16:57           ` Stephen Smalley
2004-07-29 17:06             ` James Morris
2004-07-29 17:22               ` Stephen Smalley
2004-07-29 20:05                 ` Luke Kenneth Casson Leighton
2004-07-29 20:09                   ` Stephen Smalley
2004-07-31  1:43                     ` Russell Coker
2004-07-31 16:35                       ` Luke Kenneth Casson Leighton
2004-08-01 10:31                         ` Russell Coker
2004-08-01 12:03                           ` Luke Kenneth Casson Leighton
2004-08-02 13:10                             ` Stephen Smalley
2004-08-01 12:11                           ` Luke Kenneth Casson Leighton
2004-08-02 12:38                         ` Stephen Smalley
2004-08-02 12:35                       ` Stephen Smalley
2004-07-29 20:59               ` Valdis.Kletnieks
2004-07-29 22:11                 ` Luke Kenneth Casson Leighton [this message]
2004-07-29 14:22         ` Luke Kenneth Casson Leighton
2004-07-29 14:35         ` Luke Kenneth Casson Leighton
2004-07-29 17:04           ` James Morris
2004-07-29 20:56             ` Valdis.Kletnieks
2004-07-29 12:43   ` Stephen Smalley
2004-07-29 13:53     ` Luke Kenneth Casson Leighton
2004-07-29 14:25       ` Stephen Smalley
2004-07-29 12:36 ` Stephen Smalley
2004-07-29 13:57   ` Luke Kenneth Casson Leighton

Reply instructions:

You may reply publicly to this message via plain-text email
using any one of the following methods:

* Save the following mbox file, import it into your mail client,
  and reply-to-all from there: mbox

  Avoid top-posting and favor interleaved quoting:
  https://en.wikipedia.org/wiki/Posting_style#Interleaved_style

* Reply using the --to, --cc, and --in-reply-to
  switches of git-send-email(1):

  git send-email \
    --in-reply-to=20040729221146.GO9950@lkcl.net \
    --to=lkcl@lkcl.net \
    --cc=Valdis.Kletnieks@vt.edu \
    --cc=jmorris@redhat.com \
    --cc=method@gentoo.org \
    --cc=sds@epoch.ncsc.mil \
    --cc=selinux@tycho.nsa.gov \
    /path/to/YOUR_REPLY

  https://kernel.org/pub/software/scm/git/docs/git-send-email.html

* If your mail client supports setting the In-Reply-To header
  via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line before the message body.
This is an external index of several public inboxes,
see mirroring instructions on how to clone and mirror
all data and code used by this external index.