All of lore.kernel.org
 help / color / mirror / Atom feed
* policy for k3b (and cdrecord)
@ 2004-08-17 18:33 Luke Kenneth Casson Leighton
  2004-08-18 10:54 ` Russell Coker
  0 siblings, 1 reply; 3+ messages in thread
From: Luke Kenneth Casson Leighton @ 2004-08-17 18:33 UTC (permalink / raw)
  To: SE-Linux

i'm writing a policy for k3b (kde cd burner) and cdrecord because
write access by users to /dev/hdc is banned (policy violation) and
because, well, because.

sadly, k3b uses find to search the ENTIRE drive e.g. /dev and /
and stuff and so i get a whole stack of search and read permissions
requested.

this i can put up with by banning with dontaudit: i can do this because
i actually don't _want_ users to burn CDs with k3b except from anything from
their home directory, and any excessive number of dontaudits i am
personally quite happy with.

(and for backup purposes they can have a nice shiny button on the
desktop, using a different program, which will get its own nice policy
file).

my question is, therefore:

- for more generic use, obviously k3b must be allowed to access pretty
  much anything on / so what should i put in place of all the
  dontaudits and allow k3b_t user_home_t etc. stuff?

ta,

l.

-- 
--
Truth, honesty and respect are rare commodities that all spring from
the same well: Love.  If you love yourself and everyone and everything
around you, funnily and coincidentally enough, life gets a lot better.
--
<a href="http://lkcl.net">      lkcl.net      </a> <br />
<a href="mailto:lkcl@lkcl.net"> lkcl@lkcl.net </a> <br />


--
This message was distributed to subscribers of the selinux mailing list.
If you no longer wish to subscribe, send mail to majordomo@tycho.nsa.gov with
the words "unsubscribe selinux" without quotes as the message.

^ permalink raw reply	[flat|nested] 3+ messages in thread

end of thread, other threads:[~2004-08-18 19:24 UTC | newest]

Thread overview: 3+ messages (download: mbox.gz follow: Atom feed
-- links below jump to the message on this page --
2004-08-17 18:33 policy for k3b (and cdrecord) Luke Kenneth Casson Leighton
2004-08-18 10:54 ` Russell Coker
2004-08-18 15:37   ` Luke Kenneth Casson Leighton

This is an external index of several public inboxes,
see mirroring instructions on how to clone and mirror
all data and code used by this external index.