From: Daniel J Walsh <dwalsh@redhat.com>
To: Joe Nall <joe@nall.com>
Cc: "Christopher J. PeBenito" <cpebenito@tresys.com>,
SELinux Mail List <selinux@tycho.nsa.gov>,
Eamon Walsh <ewalsh@tycho.nsa.gov>
Subject: Re: rbacsep: collapsing xserver
Date: Wed, 28 May 2008 14:38:39 -0400 [thread overview]
Message-ID: <483DA6AF.1070807@redhat.com> (raw)
In-Reply-To: <ddbc00640805281127ld1e848bs54c9f2dc53eaf8b8@mail.gmail.com>
Joe Nall wrote:
> On Wed, May 28, 2008 at 1:16 PM, Christopher J. PeBenito
> <cpebenito@tresys.com> wrote:
>> On Wed, 2008-05-28 at 11:42 -0500, Joe Nall wrote:
>>> What is the driver for the derived types? User preference files in
>>> their home directory?
>
> I'm still trying to understand the need for the derived types. What
> does the xserver need to do that is constrained by user role?
>
>>> Any opinions on spitting the display manager (gdm/xdm) policy out of
>>> the xserver policy? The current xserver policy is quite a bit bigger
>>> than apache and several times the average policy size (te + if).
>> You can blame me for that. The xdm policy used to be separate before
>> refpolicy, but it was so intertwined with the xserver policy that there
>> wasn't a sane way to write the policies separately and still keep the
>> refpolicy encapsulation. If we collapse all xservers into xserver_t, it
>> may be possible to separate xdm again. If not, xdm will be put into a
>> tunable when we get real tunable support in the compiler.
>
> What drives the complexity/policy commingling? Or, what would have to
> change to allow the policies to be separated and simplified?
>
> joe
>
> --
> This message was distributed to subscribers of the selinux mailing list.
> If you no longer wish to subscribe, send mail to majordomo@tycho.nsa.gov with
> the words "unsubscribe selinux" without quotes as the message.
I say collapse it and do not allow staff_t or user_t to execute startx.
This is what fedora does. Allowing a confined domain to start
something as complex as X windows is just a big headache. And would
probably allow lots of escalations and lots of bugs.
xdm (gdm.kdm) is starting to run lots of software before user login, so
we need to do a better job of isolating this from the xserver.
The current XAce software is far to complex to do anything usefull in my
opinion. We have way too many types and transitions. We need to
simplify down to a lot less types.
--
This message was distributed to subscribers of the selinux mailing list.
If you no longer wish to subscribe, send mail to majordomo@tycho.nsa.gov with
the words "unsubscribe selinux" without quotes as the message.
next prev parent reply other threads:[~2008-05-28 18:38 UTC|newest]
Thread overview: 24+ messages / expand[flat|nested] mbox.gz Atom feed top
2008-05-28 14:38 rbacsep: collapsing xserver Christopher J. PeBenito
2008-05-28 15:16 ` Joe Nall
2008-05-28 15:27 ` Xavier Toth
2008-05-28 16:07 ` Joe Nall
2008-05-28 16:02 ` Christopher J. PeBenito
2008-05-28 16:42 ` Joe Nall
2008-05-28 18:16 ` Christopher J. PeBenito
2008-05-28 18:27 ` Joe Nall
2008-05-28 18:38 ` Daniel J Walsh [this message]
2008-05-30 13:19 ` Xavier Toth
2008-05-30 13:47 ` Christopher J. PeBenito
2008-05-30 15:01 ` Joe Nall
2008-05-30 23:10 ` Eamon Walsh
2008-06-02 18:38 ` Christopher J. PeBenito
2008-05-29 13:04 ` Christopher J. PeBenito
2008-05-28 18:59 ` Eamon Walsh
2008-05-29 16:18 ` Xavier Toth
2008-05-29 19:50 ` Daniel J Walsh
[not found] ` <cadfc0e40805291302o18089a33wad0ea0a15e22e93d@mail.gmail.com>
2008-05-29 20:02 ` Fwd: " Xavier Toth
2008-05-30 1:04 ` Eamon Walsh
2008-05-30 13:09 ` Xavier Toth
2008-05-30 14:58 ` Xavier Toth
2008-05-30 15:05 ` Joe Nall
2008-05-30 21:43 ` Casey Schaufler
Reply instructions:
You may reply publicly to this message via plain-text email
using any one of the following methods:
* Save the following mbox file, import it into your mail client,
and reply-to-all from there: mbox
Avoid top-posting and favor interleaved quoting:
https://en.wikipedia.org/wiki/Posting_style#Interleaved_style
* Reply using the --to, --cc, and --in-reply-to
switches of git-send-email(1):
git send-email \
--in-reply-to=483DA6AF.1070807@redhat.com \
--to=dwalsh@redhat.com \
--cc=cpebenito@tresys.com \
--cc=ewalsh@tycho.nsa.gov \
--cc=joe@nall.com \
--cc=selinux@tycho.nsa.gov \
/path/to/YOUR_REPLY
https://kernel.org/pub/software/scm/git/docs/git-send-email.html
* If your mail client supports setting the In-Reply-To header
via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line
before the message body.
This is an external index of several public inboxes,
see mirroring instructions on how to clone and mirror
all data and code used by this external index.