From: Stephen Smalley <sds@tycho.nsa.gov>
To: selinux@tycho.nsa.gov
Subject: Re: [RFC][PATCH] selinux: Remove unused permission definitions
Date: Mon, 15 Jun 2015 08:41:45 -0400 [thread overview]
Message-ID: <557EC809.5050002@tycho.nsa.gov> (raw)
In-Reply-To: <20150614053349.GA5191@localhost.localdomain>
On 06/14/2015 01:33 AM, Dominick Grift wrote:
> On Wed, May 27, 2015 at 11:03:25AM -0400, Stephen Smalley wrote:
>> Remove unused permission definitions from SELinux.
>> Many of these were only ever used in pre-mainline
>> versions of SELinux, prior to Linux 2.6.0. Some of them
>> were used in the legacy network or compat_net=1 checks
>> that were disabled by default in Linux 2.6.18 and
>> fully removed in Linux 2.6.30.
>>
>> Permissions never used in mainline Linux:
>> file swapon
>
> I think that blk_file (fixed disk) swapon is actually used in my policy by fstools (i think swapon command)
It isn't checked anywhere in the SELinux kernel code, so it might be
defined in your policy but it has no meaning. The LSM hook and SELinux
hook function implementation that applied the check was never merged
into mainline.
next prev parent reply other threads:[~2015-06-15 12:42 UTC|newest]
Thread overview: 11+ messages / expand[flat|nested] mbox.gz Atom feed top
2015-05-27 15:03 [RFC][PATCH] selinux: Remove unused permission definitions Stephen Smalley
2015-05-29 21:14 ` Paul Moore
2015-05-29 21:38 ` Dominick Grift
2015-05-30 13:06 ` Paul Moore
2015-06-02 13:06 ` Christopher J. PeBenito
2015-06-03 18:45 ` Paul Moore
2015-06-14 5:33 ` Dominick Grift
2015-06-14 15:50 ` Dominick Grift
2015-06-15 12:41 ` Stephen Smalley [this message]
2016-11-21 20:48 ` Nick Kralevich
2016-11-21 21:06 ` Stephen Smalley
Reply instructions:
You may reply publicly to this message via plain-text email
using any one of the following methods:
* Save the following mbox file, import it into your mail client,
and reply-to-all from there: mbox
Avoid top-posting and favor interleaved quoting:
https://en.wikipedia.org/wiki/Posting_style#Interleaved_style
* Reply using the --to, --cc, and --in-reply-to
switches of git-send-email(1):
git send-email \
--in-reply-to=557EC809.5050002@tycho.nsa.gov \
--to=sds@tycho.nsa.gov \
--cc=selinux@tycho.nsa.gov \
/path/to/YOUR_REPLY
https://kernel.org/pub/software/scm/git/docs/git-send-email.html
* If your mail client supports setting the In-Reply-To header
via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line
before the message body.
This is an external index of several public inboxes,
see mirroring instructions on how to clone and mirror
all data and code used by this external index.