All of lore.kernel.org
 help / color / mirror / Atom feed
From: Daniel J Walsh <dwalsh@redhat.com>
To: Eamon Walsh <ewalsh@tycho.nsa.gov>
Cc: James Antill <jantill@redhat.com>, Ted X Toth <txtoth@gmail.com>,
	SE Linux <selinux@tycho.nsa.gov>
Subject: Re: In FC8 I would like to start playing with trusted X.
Date: Wed, 16 May 2007 13:07:59 -0400	[thread overview]
Message-ID: <464B3A6F.40000@redhat.com> (raw)
In-Reply-To: <464B386D.3060000@tycho.nsa.gov>

Eamon Walsh wrote:
> Daniel J Walsh wrote:
>> Ok now I was hoping the NSA guys would hop in and say.  Hey here is 
>> how you would do it.  :^)
>> Because I have no idea.  Any help would be appreciated.
>
> I've been slowly reviewing all of the 35 X protocol extensions of 
> which I'm aware, trying to revise the set of object classes and 
> permissions. I have about 8 more extensions to go.  I'm hoping to do a 
> major release of the security framework and Flask module before FC8.
>
> I think the two goals you have set forth are a reasonable target.  The 
> input goal I don't think is possible with the current implementation, 
> because the input extensions (XKB, XInput) are not covered by the 
> security hooks.  The screenshot goal should be possible.  There are 
> many screenshot apps but they all should call XCopyImage or similar, 
> which are controllable.  The problem is that the screenshot app gets a 
> BadAccess error from the denial and Xlib calls abort; it's not very 
> graceful.
>
That is what I figured.  And in order to get upstream of Xorg to fix 
these problems, we have to start showing usefulness of the access control.


>
>


--
This message was distributed to subscribers of the selinux mailing list.
If you no longer wish to subscribe, send mail to majordomo@tycho.nsa.gov with
the words "unsubscribe selinux" without quotes as the message.

  reply	other threads:[~2007-05-16 17:07 UTC|newest]

Thread overview: 10+ messages / expand[flat|nested]  mbox.gz  Atom feed  top
2007-05-15 18:44 In FC8 I would like to start playing with trusted X Daniel J Walsh
2007-05-16  0:58 ` Joshua Brindle
2007-05-16  1:33   ` Daniel J Walsh
2007-05-16 14:41 ` James Antill
2007-05-16 16:21   ` Daniel J Walsh
2007-05-16 16:59     ` Eamon Walsh
2007-05-16 17:07       ` Daniel J Walsh [this message]
2007-05-16 18:14         ` Eamon Walsh
2007-05-16 21:34           ` Ted X Toth
2007-05-18 19:53             ` Eamon Walsh

Reply instructions:

You may reply publicly to this message via plain-text email
using any one of the following methods:

* Save the following mbox file, import it into your mail client,
  and reply-to-all from there: mbox

  Avoid top-posting and favor interleaved quoting:
  https://en.wikipedia.org/wiki/Posting_style#Interleaved_style

* Reply using the --to, --cc, and --in-reply-to
  switches of git-send-email(1):

  git send-email \
    --in-reply-to=464B3A6F.40000@redhat.com \
    --to=dwalsh@redhat.com \
    --cc=ewalsh@tycho.nsa.gov \
    --cc=jantill@redhat.com \
    --cc=selinux@tycho.nsa.gov \
    --cc=txtoth@gmail.com \
    /path/to/YOUR_REPLY

  https://kernel.org/pub/software/scm/git/docs/git-send-email.html

* If your mail client supports setting the In-Reply-To header
  via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line before the message body.
This is an external index of several public inboxes,
see mirroring instructions on how to clone and mirror
all data and code used by this external index.