All of lore.kernel.org
 help / color / mirror / Atom feed
* crond_t
@ 2005-07-08 14:04 Russell Coker
  2005-07-08 14:25 ` crond_t Daniel J Walsh
  0 siblings, 1 reply; 4+ messages in thread
From: Russell Coker @ 2005-07-08 14:04 UTC (permalink / raw)
  To: SE-Linux, Daniel J Walsh

It seems that the domain crond_t needs the attribute privfd.  The number of 
things that are run from cron jobs demands it.  A user of the rawhide policy 
reported a problem running ping from a cron job on IRC.

-- 
http://www.coker.com.au/selinux/   My NSA Security Enhanced Linux packages
http://www.coker.com.au/bonnie++/  Bonnie++ hard drive benchmark
http://www.coker.com.au/postal/    Postal SMTP/POP benchmark
http://www.coker.com.au/~russell/  My home page

--
This message was distributed to subscribers of the selinux mailing list.
If you no longer wish to subscribe, send mail to majordomo@tycho.nsa.gov with
the words "unsubscribe selinux" without quotes as the message.

^ permalink raw reply	[flat|nested] 4+ messages in thread

* Re: crond_t
  2005-07-08 14:04 crond_t Russell Coker
@ 2005-07-08 14:25 ` Daniel J Walsh
  2005-07-09  3:00   ` crond_t Russell Coker
  0 siblings, 1 reply; 4+ messages in thread
From: Daniel J Walsh @ 2005-07-08 14:25 UTC (permalink / raw)
  To: russell; +Cc: SE-Linux

Russell Coker wrote:

>It seems that the domain crond_t needs the attribute privfd.  The number of 
>things that are run from cron jobs demands it.  A user of the rawhide policy 
>reported a problem running ping from a cron job on IRC.
>
>  
>
crond_t has privfd.

Are you talking about system_crond_t and friends?

-- 



--
This message was distributed to subscribers of the selinux mailing list.
If you no longer wish to subscribe, send mail to majordomo@tycho.nsa.gov with
the words "unsubscribe selinux" without quotes as the message.

^ permalink raw reply	[flat|nested] 4+ messages in thread

* Re: crond_t
  2005-07-08 14:25 ` crond_t Daniel J Walsh
@ 2005-07-09  3:00   ` Russell Coker
  2005-07-10 11:56     ` crond_t Daniel J Walsh
  0 siblings, 1 reply; 4+ messages in thread
From: Russell Coker @ 2005-07-09  3:00 UTC (permalink / raw)
  To: Daniel J Walsh; +Cc: SE-Linux

On Saturday 09 July 2005 00:25, Daniel J Walsh <dwalsh@redhat.com> wrote:
> Russell Coker wrote:
> >It seems that the domain crond_t needs the attribute privfd.  The number
> > of things that are run from cron jobs demands it.  A user of the rawhide
> > policy reported a problem running ping from a cron job on IRC.
>
> crond_t has privfd.

In which version?  selinux-policy-targeted-sources-1.24-3 doesn't have it.

> Are you talking about system_crond_t and friends?

No, the domain_auto_trans() rules from those domains give the fd use rules 
that are needed.

-- 
http://www.coker.com.au/selinux/   My NSA Security Enhanced Linux packages
http://www.coker.com.au/bonnie++/  Bonnie++ hard drive benchmark
http://www.coker.com.au/postal/    Postal SMTP/POP benchmark
http://www.coker.com.au/~russell/  My home page

--
This message was distributed to subscribers of the selinux mailing list.
If you no longer wish to subscribe, send mail to majordomo@tycho.nsa.gov with
the words "unsubscribe selinux" without quotes as the message.

^ permalink raw reply	[flat|nested] 4+ messages in thread

* Re: crond_t
  2005-07-09  3:00   ` crond_t Russell Coker
@ 2005-07-10 11:56     ` Daniel J Walsh
  0 siblings, 0 replies; 4+ messages in thread
From: Daniel J Walsh @ 2005-07-10 11:56 UTC (permalink / raw)
  To: russell; +Cc: SE-Linux

Russell Coker wrote:

>On Saturday 09 July 2005 00:25, Daniel J Walsh <dwalsh@redhat.com> wrote:
>  
>
>>Russell Coker wrote:
>>    
>>
>>>It seems that the domain crond_t needs the attribute privfd.  The number
>>>of things that are run from cron jobs demands it.  A user of the rawhide
>>>policy reported a problem running ping from a cron job on IRC.
>>>      
>>>
>>crond_t has privfd.
>>    
>>
>
>In which version?  selinux-policy-targeted-sources-1.24-3 doesn't have it.
>
>  
>
>>Are you talking about system_crond_t and friends?
>>    
>>
>
>No, the domain_auto_trans() rules from those domains give the fd use rules 
>that are needed.
>
>  
>
It is in strict policy, not in targeted.
selinux-policy-*-1.25.1-6

Dan

-- 



--
This message was distributed to subscribers of the selinux mailing list.
If you no longer wish to subscribe, send mail to majordomo@tycho.nsa.gov with
the words "unsubscribe selinux" without quotes as the message.

^ permalink raw reply	[flat|nested] 4+ messages in thread

end of thread, other threads:[~2005-07-10 11:59 UTC | newest]

Thread overview: 4+ messages (download: mbox.gz follow: Atom feed
-- links below jump to the message on this page --
2005-07-08 14:04 crond_t Russell Coker
2005-07-08 14:25 ` crond_t Daniel J Walsh
2005-07-09  3:00   ` crond_t Russell Coker
2005-07-10 11:56     ` crond_t Daniel J Walsh

This is an external index of several public inboxes,
see mirroring instructions on how to clone and mirror
all data and code used by this external index.