All of lore.kernel.org
 help / color / mirror / Atom feed
* cupsd_t and sys_admin
@ 2024-10-05  9:26 Russell Coker
  2024-10-07 19:35 ` Chris PeBenito
  0 siblings, 1 reply; 2+ messages in thread
From: Russell Coker @ 2024-10-05  9:26 UTC (permalink / raw)
  To: SELinux Reference Policy mailing list

allow cupsd_t self:capability { chown dac_override dac_read_search fowner 
fsetid ipc_lock kill setgid setuid sys_admin sys_rawio sys_resource 
sys_tty_config };

From the refpolicy the above is the capabilities line for cupsd_t.  Why does 
it have sys_admin?  I don't think it has a legitimate need to do anything that 
needs that access.  Also sys_rawio seems dubious.

virt_rw_all_image_chr_files(cupsd_t)

Also what is the above about?

-- 
My Main Blog         http://etbe.coker.com.au/
My Documents Blog    http://doc.coker.com.au/




^ permalink raw reply	[flat|nested] 2+ messages in thread

end of thread, other threads:[~2024-10-07 19:36 UTC | newest]

Thread overview: 2+ messages (download: mbox.gz follow: Atom feed
-- links below jump to the message on this page --
2024-10-05  9:26 cupsd_t and sys_admin Russell Coker
2024-10-07 19:35 ` Chris PeBenito

This is an external index of several public inboxes,
see mirroring instructions on how to clone and mirror
all data and code used by this external index.