All of lore.kernel.org
 help / color / mirror / Atom feed
* Developing a SELinux policy for antivirus - How to access /home?
@ 2010-06-18 16:20 Alice Mynona
  2010-06-18 16:52 ` Jeff Johnson
  2010-06-18 16:53 ` Daniel J Walsh
  0 siblings, 2 replies; 7+ messages in thread
From: Alice Mynona @ 2010-06-18 16:20 UTC (permalink / raw)
  To: SELinux

Hello,

I'm planning to develop a SELinux module for an antivirus software. This software should protect the system from beeing infected by 
malicious files in /home. Of course, the software will be executed in a separate domain i. e. antivirus_t.

What do you recommend to allow the antivirus software to access (and manage) files und directories under /home?

My first thought was to allow the antivirus software to manage files of the type "user_home_dir_t" and directories of the type "user_home_dir_t" by using the corresponding interfaces in the reference policy (i. e. "userdom_manage_user_home_dirs"). But what's about other filetypes like "gnome_home_t", "irc_home_t", "screen_tmp_t" and so on? Is there a general method to manage files under "/home" or do you have an another idea? Am I missing something?

Thanks in advance.

Best regards,
Alice

-- 
+ Alice Mynona
+ Email: Alice_Mynona@bian-fu.net



--
This message was distributed to subscribers of the selinux mailing list.
If you no longer wish to subscribe, send mail to majordomo@tycho.nsa.gov with
the words "unsubscribe selinux" without quotes as the message.

^ permalink raw reply	[flat|nested] 7+ messages in thread

end of thread, other threads:[~2010-06-19 10:46 UTC | newest]

Thread overview: 7+ messages (download: mbox.gz follow: Atom feed
-- links below jump to the message on this page --
2010-06-18 16:20 Developing a SELinux policy for antivirus - How to access /home? Alice Mynona
2010-06-18 16:52 ` Jeff Johnson
2010-06-18 16:53 ` Daniel J Walsh
2010-06-18 18:14   ` Alice Mynona
2010-06-18 18:50     ` Daniel J Walsh
2010-06-18 18:55     ` Stephen Smalley
2010-06-19 10:46       ` Alice Mynona

This is an external index of several public inboxes,
see mirroring instructions on how to clone and mirror
all data and code used by this external index.