From: petre rodan <kaiowas@gentoo.org>
To: SELinux <SELinux@tycho.nsa.gov>
Cc: Valdis.Kletnieks@vt.edu
Subject: Re: Still getting random execute permissions on shared libraries.
Date: Sat, 27 Nov 2004 08:49:22 +0200 [thread overview]
Message-ID: <41A82372.9040308@gentoo.org> (raw)
In-Reply-To: <200411262244.iAQMiLvE007647@turing-police.cc.vt.edu>
[-- Attachment #1: Type: text/plain, Size: 1412 bytes --]
Valdis.Kletnieks@vt.edu wrote:
> On Fri, 26 Nov 2004 21:49:22 +0200, petre rodan said:
>>I made a patch to the kernel that reverts to the old behaviour. no more execs on random files.
>>I find that changing the policy to allow those execs is not a valid solution.
>
> Why is fixing the policy not a valid solution?
I happen to use some proprietary software (think antiviruses, file integrity checkers, audit programs) that would have needed massive changes in the policy because of those execs.
it might take some time until those will be recompiled with a newer toolchain.
>>would it be feasible to send upstream a patch that would remove the 'exec on
>>read' behaviour if the kernel has selinux capabilities?
> A Very Bad Idea. Basically, you're disabling a good and reasonable security
> measure entirely, just because you can't get it to work with a *legacy* binary
> and another security measure..
those security measures were added somewhere in the rc stage of 2.6.9, a kernel that was badly needed because of the flaws it was fixing.
I needed a way to replicate the behavior of older kernels in order to keep the sanity of the system, so that patch seemed a quick solution (call it as you wish).
I agree now that it shouldn't be sent upstream, but if someone feels the need to solve <subj>, then it patching time :)
bye,
peter
--
petre rodan
<kaiowas@gentoo.org>
Developer,
Hardened Gentoo Linux
[-- Attachment #2: OpenPGP digital signature --]
[-- Type: application/pgp-signature, Size: 252 bytes --]
next prev parent reply other threads:[~2004-11-27 6:49 UTC|newest]
Thread overview: 7+ messages / expand[flat|nested] mbox.gz Atom feed top
[not found] <41A3EC21.1090200@comcast.net>
2004-11-24 13:30 ` Still getting random execute permissions on shared libraries Stephen Smalley
2004-11-24 16:14 ` Daniel J Walsh
2004-11-24 16:22 ` Stephen Smalley
2004-11-26 19:49 ` petre rodan
2004-11-26 22:44 ` Valdis.Kletnieks
2004-11-27 6:49 ` petre rodan [this message]
2004-11-29 14:38 ` Stephen Smalley
Reply instructions:
You may reply publicly to this message via plain-text email
using any one of the following methods:
* Save the following mbox file, import it into your mail client,
and reply-to-all from there: mbox
Avoid top-posting and favor interleaved quoting:
https://en.wikipedia.org/wiki/Posting_style#Interleaved_style
* Reply using the --to, --cc, and --in-reply-to
switches of git-send-email(1):
git send-email \
--in-reply-to=41A82372.9040308@gentoo.org \
--to=kaiowas@gentoo.org \
--cc=SELinux@tycho.nsa.gov \
--cc=Valdis.Kletnieks@vt.edu \
/path/to/YOUR_REPLY
https://kernel.org/pub/software/scm/git/docs/git-send-email.html
* If your mail client supports setting the In-Reply-To header
via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line
before the message body.
This is an external index of several public inboxes,
see mirroring instructions on how to clone and mirror
all data and code used by this external index.