All of lore.kernel.org
 help / color / mirror / Atom feed
* User range vs. context's range
@ 2016-01-20 20:59 Christopher J. PeBenito
  2016-01-20 21:22 ` Stephen Smalley
  0 siblings, 1 reply; 8+ messages in thread
From: Christopher J. PeBenito @ 2016-01-20 20:59 UTC (permalink / raw)
  To: SELinux List

What is the intended behavior for a user's allowed range in the policy
vs. any labels in the policy (e.g. netifcon)?  My expectation is that
the allowed range should still apply, but it doesn't seem that
checkpolicy checks that, based on what I've seen.  For example, the new
sediff test policies have this user[1]:

user added_user roles system level s1 range s1;

and checkpolicy doesn't error on this[2] later in the policy:

genfscon added_genfs / added_user:object_r:system:s0

I think this should fail compilation since s0 is not in added_user's
allowed range.



[1]
https://github.com/TresysTechnology/setools/blob/master/tests/diff_right.conf#L605
[2]
https://github.com/TresysTechnology/setools/blob/master/tests/diff_right.conf#L633

-- 
Chris PeBenito
Tresys Technology, LLC
www.tresys.com | oss.tresys.com

^ permalink raw reply	[flat|nested] 8+ messages in thread

end of thread, other threads:[~2016-01-22 15:48 UTC | newest]

Thread overview: 8+ messages (download: mbox.gz follow: Atom feed
-- links below jump to the message on this page --
2016-01-20 20:59 User range vs. context's range Christopher J. PeBenito
2016-01-20 21:22 ` Stephen Smalley
2016-01-21 13:14   ` Christopher J. PeBenito
2016-01-21 21:49     ` Stephen Smalley
2016-01-21 22:05       ` Stephen Smalley
2016-01-22 14:00       ` Christopher J. PeBenito
2016-01-22 14:07         ` Stephen Smalley
2016-01-22 15:48           ` James Carter

This is an external index of several public inboxes,
see mirroring instructions on how to clone and mirror
all data and code used by this external index.