All of lore.kernel.org
 help / color / mirror / Atom feed
* [refpolicy] gpg domains
@ 2014-10-03  8:47 Russell Coker
  2014-10-08 13:13 ` Christopher J. PeBenito
  0 siblings, 1 reply; 3+ messages in thread
From: Russell Coker @ 2014-10-03  8:47 UTC (permalink / raw)
  To: refpolicy

In Debian/Testing we have the gpg-agent launching the dbus session, which then 
launches the user session.  So we have user_t -> gpg_agent_t -> user_dbusd_t
 -> user_t.  Making this work for multiple user domains requires having 
multiple gpg_agent_t domains (which we apparently used to have).

Removing the multiple $1_gpg_t domains without removing the 
user_t/unconfined_t/staff_t split doesn't seem to be viable.

Also why do we have gpg_agent_t, gpg_helper_t, and gpg_pinentry_t?  What 
benefit does this give us over having a single domain for GPG stuff that's other 
than gpg_t?  What is the logic behind a gpg_pinentry_t/gpg_agent_t anyway?  
Are those things that can even be properly split?

-- 
My Main Blog         http://etbe.coker.com.au/
My Documents Blog    http://doc.coker.com.au/

^ permalink raw reply	[flat|nested] 3+ messages in thread

end of thread, other threads:[~2014-10-10  9:07 UTC | newest]

Thread overview: 3+ messages (download: mbox.gz follow: Atom feed
-- links below jump to the message on this page --
2014-10-03  8:47 [refpolicy] gpg domains Russell Coker
2014-10-08 13:13 ` Christopher J. PeBenito
2014-10-10  9:07   ` Dominick Grift

This is an external index of several public inboxes,
see mirroring instructions on how to clone and mirror
all data and code used by this external index.