All of lore.kernel.org
 help / color / mirror / Atom feed
From: Eamon Walsh <ewalsh@tycho.nsa.gov>
To: selinux@tycho.nsa.gov
Subject: Re: Sample policy language extension supporting per-user policy
Date: Fri, 23 Mar 2007 20:25:47 -0400	[thread overview]
Message-ID: <4604700B.1040503@tycho.nsa.gov> (raw)
In-Reply-To: <4604685B.301@tycho.nsa.gov>

Responding to a private message on-list:

 > - This discussion should happen on list,
 > - Human understandability of the source policy is a concern,

I think the language extension would be easier to understand than the 
current m4-based way of accomplishing the same thing.


 > - I don't think we want to encourage automatic type mangling, even for
 > short term implementation, as it will just cause confusion and leak
 > though audit messages and kernel APIs.

The language extension could be implemented at compile-time using 
automatic type mangling.  But if this is not possible then it could be 
built into the policy language itself.  The policy size reduction could 
only happen this way anyway.


 > - We need to make sure we are solving the real problem.

This would not really solve the problem brought up in the private 
discussion, which is how to better integrate user management into 
SELinux.  But it could help, by allowing users to be added in policy 
modules and then having existing policy pick them up.

The major problem it would solve is policy size and complexity of type 
names.


 > - Separation of Linux user management from SELinux policy seems
 > necessary, so it won't get us to the point of per-Linux-user
 > permissions.

The debate over whether or not they should be separated triggered this 
proposal, but I think it could stand on its own even if they do remain 
separated.


-- 
Eamon Walsh <ewalsh@tycho.nsa.gov>
National Security Agency


--
This message was distributed to subscribers of the selinux mailing list.
If you no longer wish to subscribe, send mail to majordomo@tycho.nsa.gov with
the words "unsubscribe selinux" without quotes as the message.

      reply	other threads:[~2007-03-24  0:25 UTC|newest]

Thread overview: 2+ messages / expand[flat|nested]  mbox.gz  Atom feed  top
2007-03-23 23:52 Sample policy language extension supporting per-user policy Eamon Walsh
2007-03-24  0:25 ` Eamon Walsh [this message]

Reply instructions:

You may reply publicly to this message via plain-text email
using any one of the following methods:

* Save the following mbox file, import it into your mail client,
  and reply-to-all from there: mbox

  Avoid top-posting and favor interleaved quoting:
  https://en.wikipedia.org/wiki/Posting_style#Interleaved_style

* Reply using the --to, --cc, and --in-reply-to
  switches of git-send-email(1):

  git send-email \
    --in-reply-to=4604700B.1040503@tycho.nsa.gov \
    --to=ewalsh@tycho.nsa.gov \
    --cc=selinux@tycho.nsa.gov \
    /path/to/YOUR_REPLY

  https://kernel.org/pub/software/scm/git/docs/git-send-email.html

* If your mail client supports setting the In-Reply-To header
  via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line before the message body.
This is an external index of several public inboxes,
see mirroring instructions on how to clone and mirror
all data and code used by this external index.