All of lore.kernel.org
 help / color / mirror / Atom feed
* Access to xdm_t
@ 2004-09-29 16:32 Thomas Bleher
  2004-09-29 17:50 ` Russell Coker
                   ` (2 more replies)
  0 siblings, 3 replies; 12+ messages in thread
From: Thomas Bleher @ 2004-09-29 16:32 UTC (permalink / raw)
  To: SELinux ML

I have a question about access to xdm_t:
With KDM 3.3 I am seeing a lot of accesses to xdm_t:fd and
xdm_t:fifo_file from user processes (say user_lpr_t and user_gpg_t)
Should these be allowed?
If yes, should xdm_t get the attribute privfd?

Also, is it OK to dontaudit access to .xsession-errors (on SuSE it lives
under ~ and I do not want to give all derived user domains access to user's
home dir). Or will this cause errors with some programs?

Thanks for your answers,
Thomas

-- 
http://www.cip.ifi.lmu.de/~bleher/selinux/ - my SELinux pages
GPG-Fingerprint: BC4F BB16 30D6 F253 E3EA  D09E C562 2BAE B2F4 ABE7

--
This message was distributed to subscribers of the selinux mailing list.
If you no longer wish to subscribe, send mail to majordomo@tycho.nsa.gov with
the words "unsubscribe selinux" without quotes as the message.

^ permalink raw reply	[flat|nested] 12+ messages in thread

end of thread, other threads:[~2004-10-01 11:09 UTC | newest]

Thread overview: 12+ messages (download: mbox.gz follow: Atom feed
-- links below jump to the message on this page --
2004-09-29 16:32 Access to xdm_t Thomas Bleher
2004-09-29 17:50 ` Russell Coker
2004-09-29 22:01   ` Luke Kenneth Casson Leighton
2004-09-30  2:47 ` Colin Walters
2004-09-30 14:52   ` Thomas Bleher
2004-09-30 16:32 ` Colin Walters
2004-09-30 19:29   ` Luke Kenneth Casson Leighton
2004-09-30 20:41     ` Russell Coker
2004-10-01  0:47     ` Colin Walters
2004-10-01  9:35       ` Luke Kenneth Casson Leighton
2004-10-01 11:09       ` Russell Coker
2004-09-30 19:48   ` Russell Coker

This is an external index of several public inboxes,
see mirroring instructions on how to clone and mirror
all data and code used by this external index.