From: Daniel J Walsh <dwalsh@redhat.com>
To: "Christopher J. PeBenito" <cpebenito@tresys.com>
Cc: SE Linux <selinux@tycho.nsa.gov>
Subject: Re: Latest diffs in policy
Date: Mon, 15 May 2006 16:54:20 -0400 [thread overview]
Message-ID: <4468EA7C.5050708@redhat.com> (raw)
In-Reply-To: <1147719382.31984.11.camel@sgc>
Christopher J. PeBenito wrote:
> Questions inline:
>
> On Mon, 2006-05-15 at 11:58 -0400, Daniel J Walsh wrote:
>
>> Add boolean to allow mount to mount any file/filesystem. (Bind Mounts).
>>
>> More fixes for auditadm role. Any chance of getting this into ref
>> policy or should I separate out the patch?
>>
>
> Is this required for LSPP?
>
>
Yes
>> Fixes for traceroute
>>
>> prelink wants to read sbin symlinks
>>
>> Mono needs to chat with unconfined_t (acquire_svc).
>>
>> Fix label on scsi_id to stop matchpathcon error message
>>
>> Lots of new network ports for hplib and http.
>>
>> Traceroute port range defined.
>>
>> Add setrans domain
>>
>> Want to associate all files with tmpfs so the user can mv /etc/FILE /tmp
>> and not blow up.
>>
>> Add clamscan policy
>>
>> Allow bluetooth to communicate with xdm pipes.
>>
>
> Fixed the XML docs for the interfaces and moved them up with the other
> xdm_t interfaces.
>
>
>> Allow sysadm to run cvs and rdisk
>>
>> Dovecod wants quota support
>>
>> ftpd needs dac override when logging in to users homedirs
>>
>> Hal wants to search all directories in case they are mount points
>>
>> Fixes to inn.if for executing inn and allowin domtrans
>>
>> ypbind needs to be able to bind to rpc ports
>>
>> postgresql wants to look at the routing table.
>>
>> pyzor domain for strict/mls policy
>>
>> rpc wants to red /dev/random
>> nfsd needs dac privs
>>
>> Added some corecmd_executable_file for prelink to work correctly
>>
>> sshd wants to read routing table
>>
>> Only want dhcp to transition to hostname everyone else should just
>> execute it.
>>
>
> How can this work without giving initrc_t sys_admin capability (e.g.,
> static IP config)?
>
>
I will have to try. Hostname is a pain in the ass....
>> More fixes for textrel_shlib_t. will they ever end
>>
>> Separation of the auditadm from secadm and sysadm changes for auditd files.
>>
>
> Filesystem association is missing. This also brings along more problems
> like labeling. There isn't much real separation between auditadm from
> the other admin roles, so this doesn't seem to have real benefits.
>
Required for LSPP. auditadm is not allowed to do anything but manage
audit subsystem.
secadmin can only manage selinux stuff. sysadmin can only do everything
not done by auditadm
and secadm.
>
>> semanage is now translated.
>>
>> semodule needs to be able to read home dir and /tmp dir since this is
>> where people are creating modules.
>>
>> ifconfig wants to read urand for ipsec setup
>>
>> unconfined domtrans to prelink and inn
>>
>
>
--
This message was distributed to subscribers of the selinux mailing list.
If you no longer wish to subscribe, send mail to majordomo@tycho.nsa.gov with
the words "unsubscribe selinux" without quotes as the message.
next prev parent reply other threads:[~2006-05-15 20:54 UTC|newest]
Thread overview: 8+ messages / expand[flat|nested] mbox.gz Atom feed top
2006-05-15 15:58 Latest diffs in policy Daniel J Walsh
2006-05-15 18:56 ` Christopher J. PeBenito
2006-05-15 20:54 ` Daniel J Walsh [this message]
2006-05-15 22:15 ` Casey Schaufler
2006-05-16 13:35 ` Christopher J. PeBenito
2006-05-16 14:44 ` Daniel J Walsh
2006-05-16 15:37 ` Christopher J. PeBenito
2006-05-17 14:58 ` Christopher J. PeBenito
Reply instructions:
You may reply publicly to this message via plain-text email
using any one of the following methods:
* Save the following mbox file, import it into your mail client,
and reply-to-all from there: mbox
Avoid top-posting and favor interleaved quoting:
https://en.wikipedia.org/wiki/Posting_style#Interleaved_style
* Reply using the --to, --cc, and --in-reply-to
switches of git-send-email(1):
git send-email \
--in-reply-to=4468EA7C.5050708@redhat.com \
--to=dwalsh@redhat.com \
--cc=cpebenito@tresys.com \
--cc=selinux@tycho.nsa.gov \
/path/to/YOUR_REPLY
https://kernel.org/pub/software/scm/git/docs/git-send-email.html
* If your mail client supports setting the In-Reply-To header
via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line
before the message body.
This is an external index of several public inboxes,
see mirroring instructions on how to clone and mirror
all data and code used by this external index.