All of lore.kernel.org
 help / color / mirror / Atom feed
* Tonights rawhide contains a fix to stop xspy.
@ 2008-02-28  4:06 Daniel J Walsh
  2008-02-28  7:38 ` Eamon Walsh
  0 siblings, 1 reply; 7+ messages in thread
From: Daniel J Walsh @ 2008-02-28  4:06 UTC (permalink / raw)
  To: Eamon Walsh, SE Linux

-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA1

Basically if you turn on xserver_object_manager boolean, no applications
will be allowed to read the x_device.  This stops xspy as you said dead
in its tracks,  but some other applications start to get AVC's around
querypointer, and eventually I hung the server.  You mentioned in
another email, that you were going to change the querypointer to a
getattr rather then a read, I think this is necessary, to make this work.


#============= mono_t ==============
allow mono_t xdm_xserver_t:x_device read;

#============= unconfined_t ==============
allow unconfined_t xdm_xserver_t:x_device read;

#============= xdm_t ==============
allow xdm_t xdm_xserver_t:x_device read;

type=USER_AVC msg=audit(1204170576.402:774): user pid=2729 uid=0
auid=4294967295 subj=system_u:system_r:xdm_xserver_t:s0-s0:c0.c1023
msg='avc:  denied  { read } for request=X11:QueryPointer comm=mono
xdevice="Virtual core pointer"
scontext=unconfined_u:unconfined_r:mono_t:s0
tcontext=system_u:system_r:xdm_xserver_t:s0-s0:c0.c1023 tclass=x_device
: exe="/usr/bin/Xorg" (sauid=0, hostname=?, addr=?, terminal=?)'
-----BEGIN PGP SIGNATURE-----
Version: GnuPG v1.4.8 (GNU/Linux)
Comment: Using GnuPG with Fedora - http://enigmail.mozdev.org

iEYEARECAAYFAkfGM1IACgkQrlYvE4MpobNFCACgswhn3LUm6w7TN1WQTJMjkQEr
Y4IAoI88/8sGgw8ZU3ibGp1cpzwUkDk5
=Q+pt
-----END PGP SIGNATURE-----

--
This message was distributed to subscribers of the selinux mailing list.
If you no longer wish to subscribe, send mail to majordomo@tycho.nsa.gov with
the words "unsubscribe selinux" without quotes as the message.

^ permalink raw reply	[flat|nested] 7+ messages in thread

end of thread, other threads:[~2008-03-03 22:05 UTC | newest]

Thread overview: 7+ messages (download: mbox.gz follow: Atom feed
-- links below jump to the message on this page --
2008-02-28  4:06 Tonights rawhide contains a fix to stop xspy Daniel J Walsh
2008-02-28  7:38 ` Eamon Walsh
2008-02-28 14:13   ` Daniel J Walsh
2008-02-29  4:09     ` Eamon Walsh
2008-02-29 13:51       ` Daniel J Walsh
2008-03-03 22:04         ` Eamon Walsh
2008-02-29 14:48       ` Tom London

This is an external index of several public inboxes,
see mirroring instructions on how to clone and mirror
all data and code used by this external index.