All of lore.kernel.org
 help / color / mirror / Atom feed
From: Ole Kliemann <ole@plastictree.net>
To: Richard Haines <richard_c_haines@btinternet.com>
Cc: selinux@tycho.nsa.gov
Subject: Re: Information about XSELinux
Date: Thu, 19 Jul 2012 16:18:23 +0200	[thread overview]
Message-ID: <20120719141823.GA19890@telvanni> (raw)
In-Reply-To: <1342534966.11916.YahooMailClassic@web87705.mail.ir2.yahoo.com>

[-- Attachment #1: Type: text/plain, Size: 2612 bytes --]

Thanks Richard, your X-setest tool is quite helpful to understand 
what's going on.

Under Ubuntu I compiled the xserver-xorg package and manually 
enabled --enable-selinux. Now it's working here. (They are at 
1.11.4). I'm now writing a simple policy from scratch to extend 
traditional linux user seperation to X.

I have one question though: This bug that appears under Fedora 
and crashes the Xserver, is that a bug in the xorg sources or 
something that came with patches from Fedora?

And how often have things like this happend in the past? I'm 
planing on using this on a production system and ask myself how 
careful I will have to be with updates to xorg in the future.

On Tue, Jul 17, 2012 at 03:22:46PM +0100, Richard Haines wrote:
> I've attached some updated XSELinux information that I've been working on for the next version of the SELinux Notebook (old XSELinux stuff at: http://selinuxproject.org/page/NB_XWIN).
> 
> The XSELinux module is in the X source and always included with Fedora - I don't use other distributions so don't know whether they enable it in their builds or not. If they do build it, then you need the reference policy modules and then enable the xserver boolean as follows:
> 
>      setsebool xserver_object_manager true
> 
> I'm not sure what the current development status is but I've submitted a couple of patches (the last one for xorg-x11-server-1.12.2 as it core dumps when XSELinux is enabled with the above boolean).
> 
> I've written a few apps to 'play with XSELinux' that are mentioned in the text. Let me know if you would like the source (tested on Fedora 16/17).
> 
> I have not really done anything with the XSELinux reference policy modules as they come with Fedora and seem to work (well for my limited use anyway).
> 
> Richard
> 
> --- On Mon, 16/7/12, Ole Kliemann <ole@plastictree.net> wrote:
> 
> > From: Ole Kliemann <ole@plastictree.net>
> > Subject: Information about XSELinux
> > To: selinux@tycho.nsa.gov
> > Date: Monday, 16 July, 2012, 17:10
> > Hi everyone!
> > 
> > I'm desperately trying to implement proper privilege
> > seperation 
> > while using X.
> > 
> > Currently I'm looking into XSELinux but am having a really
> > hard 
> > time finding any information, documention etc.
> > 
> > What's the development status?
> > Where can I get it?
> > Is it included in any major distributions? (Currently using
> > 
> > Ubuntu 12.04)
> > 
> > Any hint on where to find information would be highly 
> > appreciated!
> > 
> > Many thanks in advance and best regards,
> > Ole
> >



[-- Attachment #2: Digital signature --]
[-- Type: application/pgp-signature, Size: 198 bytes --]

       reply	other threads:[~2012-07-19 14:18 UTC|newest]

Thread overview: 13+ messages / expand[flat|nested]  mbox.gz  Atom feed  top
     [not found] <1342534966.11916.YahooMailClassic@web87705.mail.ir2.yahoo.com>
2012-07-19 14:18 ` Ole Kliemann [this message]
2012-07-19 17:01   ` Information about XSELinux Richard Haines
2012-07-23 14:12     ` Ted Toth
2012-07-24 11:05       ` Ole Kliemann
2012-07-16 16:10 Ole Kliemann
2012-07-16 18:23 ` Russell Coker
2012-07-16 22:18   ` Ole Kliemann
2012-07-19 13:29     ` Stephen Smalley
2012-07-19 14:10       ` Daniel J Walsh
2012-07-19 14:44         ` Ole Kliemann
2012-07-27  4:02           ` Russell Coker
2012-08-07 12:53             ` Ole Kliemann
2012-07-17 17:31 ` James Carter

Reply instructions:

You may reply publicly to this message via plain-text email
using any one of the following methods:

* Save the following mbox file, import it into your mail client,
  and reply-to-all from there: mbox

  Avoid top-posting and favor interleaved quoting:
  https://en.wikipedia.org/wiki/Posting_style#Interleaved_style

* Reply using the --to, --cc, and --in-reply-to
  switches of git-send-email(1):

  git send-email \
    --in-reply-to=20120719141823.GA19890@telvanni \
    --to=ole@plastictree.net \
    --cc=richard_c_haines@btinternet.com \
    --cc=selinux@tycho.nsa.gov \
    /path/to/YOUR_REPLY

  https://kernel.org/pub/software/scm/git/docs/git-send-email.html

* If your mail client supports setting the In-Reply-To header
  via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line before the message body.
This is an external index of several public inboxes,
see mirroring instructions on how to clone and mirror
all data and code used by this external index.