All of lore.kernel.org
 help / color / mirror / Atom feed
* [refpolicy] Enable login and use the whole system from /dev/console
@ 2010-12-21  3:11 HarryCiao
  2011-01-05 15:53 ` Christopher J. PeBenito
  0 siblings, 1 reply; 4+ messages in thread
From: HarryCiao @ 2010-12-21  3:11 UTC (permalink / raw)
  To: refpolicy


Hi Chris,
 
I remembered months ago we'd been talking about enabling the support of /dev/console so that users could log in from it and then use the system as normal. At that time you'd concluded that you may endorse the support for the console device by a boolean.
 
While, here is the patch, I've made use of the CUSTOM_BUILDOPT in build.conf to define a compile flag to trigger following supports for the /dev/console, I think a build flag would be better than a boolean in that you could enable/disable it according to the real deployment of your system.
 
Provide following supports for the /dev/console:
 1. Make it able to be used as a login device;
 2. Make users able to login from it;
 3. Make many userspace domains able to read from it, so that
     the corresponding applications could be run on the console;
 4. Make relevant domains able to relabel it as well as tty/pty devices,
     for example, you could use newrole on the console.
 5. Mark it as a secure device to change the security level.
 
Any comments just let me know, thanks a lot!
 
Best regards,
Harry 		 	   		  
-------------- next part --------------
An HTML attachment was scrubbed...
URL: http://oss.tresys.com/pipermail/refpolicy/attachments/20101221/6d779552/attachment-0001.html 
-------------- next part --------------
A non-text attachment was scrubbed...
Name: 0001-login-and-use-system-from-console.patch
Type: application/octet-stream
Size: 6895 bytes
Desc: not available
Url : http://oss.tresys.com/pipermail/refpolicy/attachments/20101221/6d779552/attachment-0001.obj 

^ permalink raw reply	[flat|nested] 4+ messages in thread

end of thread, other threads:[~2011-01-14 19:48 UTC | newest]

Thread overview: 4+ messages (download: mbox.gz follow: Atom feed
-- links below jump to the message on this page --
2010-12-21  3:11 [refpolicy] Enable login and use the whole system from /dev/console HarryCiao
2011-01-05 15:53 ` Christopher J. PeBenito
     [not found]   ` <SNT139-w22E3978CFC050DC3020493AB0B0@phx.gbl>
     [not found]     ` <4D27187C.3050808@tresys.com>
2011-01-10 11:17       ` [refpolicy] [v2] " HarryCiao
2011-01-14 19:48         ` Christopher J. PeBenito

This is an external index of several public inboxes,
see mirroring instructions on how to clone and mirror
all data and code used by this external index.