All of lore.kernel.org
 help / color / mirror / Atom feed
From: Daniel J Walsh <dwalsh@redhat.com>
To: "Christopher J. PeBenito" <cpebenito@tresys.com>
Cc: SE Linux <selinux@tycho.nsa.gov>
Subject: Re: Latest Diffs 11/29
Date: Mon, 04 Dec 2006 15:59:13 -0500	[thread overview]
Message-ID: <45748C21.1060201@redhat.com> (raw)
In-Reply-To: <1165264006.4220.57.camel@sgc>

Christopher J. PeBenito wrote:
> On Wed, 2006-11-29 at 17:06 -0500, Daniel J Walsh wrote:
>   
>> Why does loadkeys built this way.  Trying this interface blew up in 
>> targeted policy.
>>     
>
> I cannot reproduce this.
>
>   
The interface blew up when trying to be used in a modular policy.  
Basically I was experimenting with
getting unconfined_t to transition to user_mozilla_t
>> I think the hi_reserved_port_t change is good.
>>     
>
> Its close, I think we need to think about changing the "rpc ports"
> concept, since it doesn't seem limited to just rpc.
>
>   
>> Fixes for polyinstatiated needs rmdir
>>     
>
> Need more explanation for login programs adding and removing user home
> directories for polyinstantiation.
>
>   
>> Cups changes for MLS
>>     
>
> I don't agree with the cupsd file change, the binary itself isn't
> sensitive.  Reordered other changes.
>
>   
>> ypxfr has moved and needs policy fixes
>>     
>
> Kept the bin search perms for compat.
>
>   
>> Dont want to dontaudit searches of var_yp_t so setroubleshoot will work 
>> correctly.
>>     
>
>   
>> nmbd_t needs to be able to unlink log files
>>     
>
> Why?  This would be a bad thing, IMO.
>
>   
Agreed, but we break samba functionality.  Maybe a boolean?
>> Fixes for swat
>>     
>
> Changing the log access to write?  Also seems like a bad thing, though
> not quite as bad since its an admin tool.
>
>   
>> tftpd uses ypbind
>>     
>
> made this optional
>
>   
>> mkswap should not be fsadm_exec_t, it is SELinux aware.
>>     
>
> Why is mkswap aware?  Why would it not be fsadm_exec_t, it will still
> have to write to the fixed disk device.
>
>   
Needs a new policy if you want.  mkswap now labels file swapfile_t.  Not 
elegant but it works. 
>> I have removed some hide_broken_symptoms thinking they are all fixed, 
>> but do you  want these around for RHEL4?
>>     
>
> Yes.
>
>   
>> depmod deletes kernel modules
>>     
>
> Why?
>
>   
>> Added policy for system-config-selinux, basically a superset of 
>> semanage_t, currently unconfined, but need transition rules to maintain 
>> context in /etc/selinux/TYPE directories.
>>     
>
> Need explanation for changes to manage_default_contexts and
> manage_selinux_config.
>
> Why are init scripts running setsebool?
>
>   
ypbind start/stop turns on the boolean.  Probably ok for targeted not 
for other platforms.
> Dropping semanage_gui_t, as its not upstream.  Selinuxutil should only
> be checkpolicy and policycoreutils programs.
>
> I don't think newrole should use the login program interface.
>
> Why do you have setfiles exec'ing init scripts?
>
>   
>> Additional rules for to get load_policy to work with MLS
>>     
>
> Need more clarification on this one.
>
>   

>> Fix RealPlayer file specification, additional unconfined_execmem_exec_t 
>> domains.
>>     
>
> Just like with mplayer, we want vmware executables labeled in the vmware
> module.
>
>   
>> xen fixes, new images directory
>>     
>
> Why is this needed:
> +	allow $1 xdm_xserver_t:process siginh;
>
>   
Needed to get transition for rhgb to xserver to work.
> Can you elaborate as to why multipath (dm/lvm) needs net_admin?  A
> cursory look through the docs doesn't mention the network at all.
>
> Changed printk_device_t to kmsg_device_t.
>
>   


--
This message was distributed to subscribers of the selinux mailing list.
If you no longer wish to subscribe, send mail to majordomo@tycho.nsa.gov with
the words "unsubscribe selinux" without quotes as the message.

      reply	other threads:[~2006-12-04 20:58 UTC|newest]

Thread overview: 3+ messages / expand[flat|nested]  mbox.gz  Atom feed  top
2006-11-29 22:06 Latest Diffs 11/29 Daniel J Walsh
2006-12-04 20:26 ` Christopher J. PeBenito
2006-12-04 20:59   ` Daniel J Walsh [this message]

Reply instructions:

You may reply publicly to this message via plain-text email
using any one of the following methods:

* Save the following mbox file, import it into your mail client,
  and reply-to-all from there: mbox

  Avoid top-posting and favor interleaved quoting:
  https://en.wikipedia.org/wiki/Posting_style#Interleaved_style

* Reply using the --to, --cc, and --in-reply-to
  switches of git-send-email(1):

  git send-email \
    --in-reply-to=45748C21.1060201@redhat.com \
    --to=dwalsh@redhat.com \
    --cc=cpebenito@tresys.com \
    --cc=selinux@tycho.nsa.gov \
    /path/to/YOUR_REPLY

  https://kernel.org/pub/software/scm/git/docs/git-send-email.html

* If your mail client supports setting the In-Reply-To header
  via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line before the message body.
This is an external index of several public inboxes,
see mirroring instructions on how to clone and mirror
all data and code used by this external index.