All of lore.kernel.org
 help / color / mirror / Atom feed
* Enabling policy capabilities
@ 2008-04-10 13:38 Stephen Smalley
  2008-04-10 14:01 ` Paul Moore
  2008-04-10 16:03 ` Daniel J Walsh
  0 siblings, 2 replies; 4+ messages in thread
From: Stephen Smalley @ 2008-04-10 13:38 UTC (permalink / raw)
  To: Eric Paris, Daniel J Walsh, Paul Moore, Christopher J. PeBenito; +Cc: selinux

Where do we stand on actually enabling policy capabilities in policy so
that people can start using newer features that depend on them?

I've definitely seen patches adding permissions for the peer checks, so
is there anything preventing us from trying to enable
network_peer_controls in policy and seeing what breaks (after Fedora 9
at this point, I suppose - unfortunate that we didn't enable it sooner)?

I haven't seen patches adding permissions for open other than just to
define them, IIRC.  So enabling open_perms would be rather bad right now
except for unconfined domains.  As a possible strategy for gradual
roll-out of open perm, we could add open everywhere there is a read or
write granted, enable the open_perms capability, verify no breakage, and
then gradually remove open permission where we know it to be unneeded.

-- 
Stephen Smalley
National Security Agency


--
This message was distributed to subscribers of the selinux mailing list.
If you no longer wish to subscribe, send mail to majordomo@tycho.nsa.gov with
the words "unsubscribe selinux" without quotes as the message.

^ permalink raw reply	[flat|nested] 4+ messages in thread

end of thread, other threads:[~2008-04-18 14:21 UTC | newest]

Thread overview: 4+ messages (download: mbox.gz follow: Atom feed
-- links below jump to the message on this page --
2008-04-10 13:38 Enabling policy capabilities Stephen Smalley
2008-04-10 14:01 ` Paul Moore
2008-04-18 14:21   ` Christopher J. PeBenito
2008-04-10 16:03 ` Daniel J Walsh

This is an external index of several public inboxes,
see mirroring instructions on how to clone and mirror
all data and code used by this external index.