From: dwalsh@redhat.com (Daniel J Walsh)
To: refpolicy@oss.tresys.com
Subject: [refpolicy] [RFC] Add security class and access vector permissions for systemd
Date: Mon, 11 Nov 2013 10:19:31 -0500 [thread overview]
Message-ID: <5280F583.5020307@redhat.com> (raw)
In-Reply-To: <1384179151-1528-1-git-send-email-bigon@debian.org>
-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA1
On 11/11/2013 09:12 AM, Laurent Bigonville wrote:
> From: Laurent Bigonville <bigon@bigon.be>
>
> This patch add the necessary security class and permissions for systemd.
>
> Fedora seems to add more permissions than the one that are actually used in
> the source, I'm not too sure why, Daniel I guess you could help here?
>
Here is the current Fedora_flask patch.
You seem to be missing some access checks from service.
The Enable/Disable/Reload are caused by systemd generating its own internal
runtime unit files. and probably asking the wrong question. I think we need
to fix systemd to ask a question based on the service not the system for these
so they can be eliminated.
ptrace_child kernel patch has not been upstreamed, but the idea here is to
allow users to ptrace child processes rather then picking a random pid.
compromize_kernel in mac_admin2 is used to indicate that you are doing
something that could/would break secure_boot, (I believe).
+ getnetgrp
+ shmemnetgrp
Are new checks used by nscd.
+class proxy
+{
+ read
+}
Is a new service used for gssproxy.
-----BEGIN PGP SIGNATURE-----
Version: GnuPG v1.4.15 (GNU/Linux)
Comment: Using GnuPG with Thunderbird - http://www.enigmail.net/
iEYEARECAAYFAlKA9YMACgkQrlYvE4MpobMMaQCdGO2AzzanIAkIyBFMzdDIG+e0
rQ0AoJuM1ccR6FjmHT2yQG3ByIeUgiDS
=S7u5
-----END PGP SIGNATURE-----
-------------- next part --------------
A non-text attachment was scrubbed...
Name: fedora_flask.patch
Type: text/x-patch
Size: 1361 bytes
Desc: not available
Url : http://oss.tresys.com/pipermail/refpolicy/attachments/20131111/d4ca4535/attachment.bin
prev parent reply other threads:[~2013-11-11 15:19 UTC|newest]
Thread overview: 2+ messages / expand[flat|nested] mbox.gz Atom feed top
2013-11-11 14:12 [refpolicy] [RFC] Add security class and access vector permissions for systemd Laurent Bigonville
2013-11-11 15:19 ` Daniel J Walsh [this message]
Reply instructions:
You may reply publicly to this message via plain-text email
using any one of the following methods:
* Save the following mbox file, import it into your mail client,
and reply-to-all from there: mbox
Avoid top-posting and favor interleaved quoting:
https://en.wikipedia.org/wiki/Posting_style#Interleaved_style
* Reply using the --to, --cc, and --in-reply-to
switches of git-send-email(1):
git send-email \
--in-reply-to=5280F583.5020307@redhat.com \
--to=dwalsh@redhat.com \
--cc=refpolicy@oss.tresys.com \
/path/to/YOUR_REPLY
https://kernel.org/pub/software/scm/git/docs/git-send-email.html
* If your mail client supports setting the In-Reply-To header
via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line
before the message body.
This is an external index of several public inboxes,
see mirroring instructions on how to clone and mirror
all data and code used by this external index.