All of lore.kernel.org
 help / color / mirror / Atom feed
* What domain should the X server run in
@ 2007-10-25 17:27 Eamon Walsh
  2007-10-25 18:50 ` Christopher J. PeBenito
  2007-10-26 12:52 ` Russell Coker
  0 siblings, 2 replies; 7+ messages in thread
From: Eamon Walsh @ 2007-10-25 17:27 UTC (permalink / raw)
  To: SELinux List; +Cc: Christopher J. PeBenito, Daniel J Walsh

The X server runs as xdm_xserver_t if it is started from a display
manager.  It runs as user_xserver_t if it is started with startx.

Is the X server part of the user's session or not?

If it is, then it should always run as user_xserver_t, and the display
managers should be "fixed" to label the X server with the user's context
at login time.

It if isn't, then it should always run in the same domain, and
startx/xinit should be "fixed" to transition into this context.

 From my perspective I would favor the latter option for now since it's 
easier to write policy for.  The user's individual windows can be 
labeled with a per-user type, maintaining separation.


-- 
Eamon Walsh <ewalsh@tycho.nsa.gov>
National Security Agency


--
This message was distributed to subscribers of the selinux mailing list.
If you no longer wish to subscribe, send mail to majordomo@tycho.nsa.gov with
the words "unsubscribe selinux" without quotes as the message.

^ permalink raw reply	[flat|nested] 7+ messages in thread

end of thread, other threads:[~2007-10-26 18:15 UTC | newest]

Thread overview: 7+ messages (download: mbox.gz follow: Atom feed
-- links below jump to the message on this page --
2007-10-25 17:27 What domain should the X server run in Eamon Walsh
2007-10-25 18:50 ` Christopher J. PeBenito
2007-10-25 19:57   ` Eamon Walsh
2007-10-26 12:52 ` Russell Coker
2007-10-26 15:43   ` Casey Schaufler
2007-10-26 16:56     ` Russell Coker
2007-10-26 18:15       ` Casey Schaufler

This is an external index of several public inboxes,
see mirroring instructions on how to clone and mirror
all data and code used by this external index.