From: Daniel J Walsh <dwalsh@redhat.com>
To: "Christopher J. PeBenito" <cpebenito@tresys.com>
Cc: SE Linux <selinux@tycho.nsa.gov>
Subject: Re: Suggested global change to policy
Date: Thu, 22 May 2008 10:00:45 -0400 [thread overview]
Message-ID: <48357C8D.5040408@redhat.com> (raw)
In-Reply-To: <1211462263.11188.95.camel@gorn>
Christopher J. PeBenito wrote:
> On Wed, 2008-05-21 at 11:59 -0400, Daniel J Walsh wrote:
>> Remove all init programs calls to
>> sysadm_dontaudit_list_home_dirs and put that call in the
>>
>> init_system_domain and init_daemon_domain
>
Well the whole cause of this avc is apps doing a getcwd() call when they
start up. Which seems to be build into glibc? Or just executables in
Linux. So any app that gets started by an administrator sitting in the
/root directory requires this dontaudit rule. If you look though the
policy this rule is everywhere for both types of init domains.
> I might be able to buy that for the latter, but I don't see it for the
> former.
>
>> That way we can think about making role/sysadm a module.
>>
>> Of course I believe the /root should have a special context of
>> admin_home_t and not be affected by whether or not you have sysadm
>> policy defined.
>
> In the RBAC separation branch I was planning to have all the roles have
> the same home directory type anyway (owned by the userdomain module).
> If it ends up that we still need to have a type-based separation between
> unpriv user and admin user home directories, then it will end up being
> as you suggest above.
>
As long as they are different. Allowing any confined app to write to
/root should be heavily constrained while writing to random users home
directories is a lot more common.
--
This message was distributed to subscribers of the selinux mailing list.
If you no longer wish to subscribe, send mail to majordomo@tycho.nsa.gov with
the words "unsubscribe selinux" without quotes as the message.
prev parent reply other threads:[~2008-05-22 14:00 UTC|newest]
Thread overview: 3+ messages / expand[flat|nested] mbox.gz Atom feed top
2008-05-21 15:59 Suggested global change to policy Daniel J Walsh
2008-05-22 13:17 ` Christopher J. PeBenito
2008-05-22 14:00 ` Daniel J Walsh [this message]
Reply instructions:
You may reply publicly to this message via plain-text email
using any one of the following methods:
* Save the following mbox file, import it into your mail client,
and reply-to-all from there: mbox
Avoid top-posting and favor interleaved quoting:
https://en.wikipedia.org/wiki/Posting_style#Interleaved_style
* Reply using the --to, --cc, and --in-reply-to
switches of git-send-email(1):
git send-email \
--in-reply-to=48357C8D.5040408@redhat.com \
--to=dwalsh@redhat.com \
--cc=cpebenito@tresys.com \
--cc=selinux@tycho.nsa.gov \
/path/to/YOUR_REPLY
https://kernel.org/pub/software/scm/git/docs/git-send-email.html
* If your mail client supports setting the In-Reply-To header
via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line
before the message body.
This is an external index of several public inboxes,
see mirroring instructions on how to clone and mirror
all data and code used by this external index.