All of lore.kernel.org
 help / color / mirror / Atom feed
From: Eamon Walsh <ewalsh@tycho.nsa.gov>
To: Daniel J Walsh <dwalsh@redhat.com>
Cc: James Antill <jantill@redhat.com>, Ted X Toth <txtoth@gmail.com>,
	SE Linux <selinux@tycho.nsa.gov>
Subject: Re: In FC8 I would like to start playing with trusted X.
Date: Wed, 16 May 2007 12:59:25 -0400	[thread overview]
Message-ID: <464B386D.3060000@tycho.nsa.gov> (raw)
In-Reply-To: <464B2F95.7090700@redhat.com>

Daniel J Walsh wrote:
> Ok now I was hoping the NSA guys would hop in and say.  Hey here is how 
> you would do it.  :^)
> Because I have no idea.  Any help would be appreciated.

I've been slowly reviewing all of the 35 X protocol extensions of which 
I'm aware, trying to revise the set of object classes and permissions. 
I have about 8 more extensions to go.  I'm hoping to do a major release 
of the security framework and Flask module before FC8.

I think the two goals you have set forth are a reasonable target.  The 
input goal I don't think is possible with the current implementation, 
because the input extensions (XKB, XInput) are not covered by the 
security hooks.  The screenshot goal should be possible.  There are many 
screenshot apps but they all should call XCopyImage or similar, which 
are controllable.  The problem is that the screenshot app gets a 
BadAccess error from the denial and Xlib calls abort; it's not very 
graceful.



-- 
Eamon Walsh <ewalsh@tycho.nsa.gov>
National Security Agency

--
This message was distributed to subscribers of the selinux mailing list.
If you no longer wish to subscribe, send mail to majordomo@tycho.nsa.gov with
the words "unsubscribe selinux" without quotes as the message.

  reply	other threads:[~2007-05-16 16:59 UTC|newest]

Thread overview: 10+ messages / expand[flat|nested]  mbox.gz  Atom feed  top
2007-05-15 18:44 In FC8 I would like to start playing with trusted X Daniel J Walsh
2007-05-16  0:58 ` Joshua Brindle
2007-05-16  1:33   ` Daniel J Walsh
2007-05-16 14:41 ` James Antill
2007-05-16 16:21   ` Daniel J Walsh
2007-05-16 16:59     ` Eamon Walsh [this message]
2007-05-16 17:07       ` Daniel J Walsh
2007-05-16 18:14         ` Eamon Walsh
2007-05-16 21:34           ` Ted X Toth
2007-05-18 19:53             ` Eamon Walsh

Reply instructions:

You may reply publicly to this message via plain-text email
using any one of the following methods:

* Save the following mbox file, import it into your mail client,
  and reply-to-all from there: mbox

  Avoid top-posting and favor interleaved quoting:
  https://en.wikipedia.org/wiki/Posting_style#Interleaved_style

* Reply using the --to, --cc, and --in-reply-to
  switches of git-send-email(1):

  git send-email \
    --in-reply-to=464B386D.3060000@tycho.nsa.gov \
    --to=ewalsh@tycho.nsa.gov \
    --cc=dwalsh@redhat.com \
    --cc=jantill@redhat.com \
    --cc=selinux@tycho.nsa.gov \
    --cc=txtoth@gmail.com \
    /path/to/YOUR_REPLY

  https://kernel.org/pub/software/scm/git/docs/git-send-email.html

* If your mail client supports setting the In-Reply-To header
  via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line before the message body.
This is an external index of several public inboxes,
see mirroring instructions on how to clone and mirror
all data and code used by this external index.