* crond_t
@ 2005-07-08 14:04 Russell Coker
2005-07-08 14:25 ` crond_t Daniel J Walsh
0 siblings, 1 reply; 4+ messages in thread
From: Russell Coker @ 2005-07-08 14:04 UTC (permalink / raw)
To: SE-Linux, Daniel J Walsh
It seems that the domain crond_t needs the attribute privfd. The number of
things that are run from cron jobs demands it. A user of the rawhide policy
reported a problem running ping from a cron job on IRC.
--
http://www.coker.com.au/selinux/ My NSA Security Enhanced Linux packages
http://www.coker.com.au/bonnie++/ Bonnie++ hard drive benchmark
http://www.coker.com.au/postal/ Postal SMTP/POP benchmark
http://www.coker.com.au/~russell/ My home page
--
This message was distributed to subscribers of the selinux mailing list.
If you no longer wish to subscribe, send mail to majordomo@tycho.nsa.gov with
the words "unsubscribe selinux" without quotes as the message.
^ permalink raw reply [flat|nested] 4+ messages in thread
* Re: crond_t
2005-07-08 14:04 crond_t Russell Coker
@ 2005-07-08 14:25 ` Daniel J Walsh
2005-07-09 3:00 ` crond_t Russell Coker
0 siblings, 1 reply; 4+ messages in thread
From: Daniel J Walsh @ 2005-07-08 14:25 UTC (permalink / raw)
To: russell; +Cc: SE-Linux
Russell Coker wrote:
>It seems that the domain crond_t needs the attribute privfd. The number of
>things that are run from cron jobs demands it. A user of the rawhide policy
>reported a problem running ping from a cron job on IRC.
>
>
>
crond_t has privfd.
Are you talking about system_crond_t and friends?
--
--
This message was distributed to subscribers of the selinux mailing list.
If you no longer wish to subscribe, send mail to majordomo@tycho.nsa.gov with
the words "unsubscribe selinux" without quotes as the message.
^ permalink raw reply [flat|nested] 4+ messages in thread
* Re: crond_t
2005-07-08 14:25 ` crond_t Daniel J Walsh
@ 2005-07-09 3:00 ` Russell Coker
2005-07-10 11:56 ` crond_t Daniel J Walsh
0 siblings, 1 reply; 4+ messages in thread
From: Russell Coker @ 2005-07-09 3:00 UTC (permalink / raw)
To: Daniel J Walsh; +Cc: SE-Linux
On Saturday 09 July 2005 00:25, Daniel J Walsh <dwalsh@redhat.com> wrote:
> Russell Coker wrote:
> >It seems that the domain crond_t needs the attribute privfd. The number
> > of things that are run from cron jobs demands it. A user of the rawhide
> > policy reported a problem running ping from a cron job on IRC.
>
> crond_t has privfd.
In which version? selinux-policy-targeted-sources-1.24-3 doesn't have it.
> Are you talking about system_crond_t and friends?
No, the domain_auto_trans() rules from those domains give the fd use rules
that are needed.
--
http://www.coker.com.au/selinux/ My NSA Security Enhanced Linux packages
http://www.coker.com.au/bonnie++/ Bonnie++ hard drive benchmark
http://www.coker.com.au/postal/ Postal SMTP/POP benchmark
http://www.coker.com.au/~russell/ My home page
--
This message was distributed to subscribers of the selinux mailing list.
If you no longer wish to subscribe, send mail to majordomo@tycho.nsa.gov with
the words "unsubscribe selinux" without quotes as the message.
^ permalink raw reply [flat|nested] 4+ messages in thread
* Re: crond_t
2005-07-09 3:00 ` crond_t Russell Coker
@ 2005-07-10 11:56 ` Daniel J Walsh
0 siblings, 0 replies; 4+ messages in thread
From: Daniel J Walsh @ 2005-07-10 11:56 UTC (permalink / raw)
To: russell; +Cc: SE-Linux
Russell Coker wrote:
>On Saturday 09 July 2005 00:25, Daniel J Walsh <dwalsh@redhat.com> wrote:
>
>
>>Russell Coker wrote:
>>
>>
>>>It seems that the domain crond_t needs the attribute privfd. The number
>>>of things that are run from cron jobs demands it. A user of the rawhide
>>>policy reported a problem running ping from a cron job on IRC.
>>>
>>>
>>crond_t has privfd.
>>
>>
>
>In which version? selinux-policy-targeted-sources-1.24-3 doesn't have it.
>
>
>
>>Are you talking about system_crond_t and friends?
>>
>>
>
>No, the domain_auto_trans() rules from those domains give the fd use rules
>that are needed.
>
>
>
It is in strict policy, not in targeted.
selinux-policy-*-1.25.1-6
Dan
--
--
This message was distributed to subscribers of the selinux mailing list.
If you no longer wish to subscribe, send mail to majordomo@tycho.nsa.gov with
the words "unsubscribe selinux" without quotes as the message.
^ permalink raw reply [flat|nested] 4+ messages in thread
end of thread, other threads:[~2005-07-10 11:59 UTC | newest]
Thread overview: 4+ messages (download: mbox.gz follow: Atom feed
-- links below jump to the message on this page --
2005-07-08 14:04 crond_t Russell Coker
2005-07-08 14:25 ` crond_t Daniel J Walsh
2005-07-09 3:00 ` crond_t Russell Coker
2005-07-10 11:56 ` crond_t Daniel J Walsh
This is an external index of several public inboxes,
see mirroring instructions on how to clone and mirror
all data and code used by this external index.