From: Casey Schaufler <casey@schaufler-ca.com>
To: russell@coker.com.au, SE-Linux <selinux@tycho.nsa.gov>
Cc: Jim Meyering <jim@meyering.net>
Subject: Re: ls in Debian/Unstable
Date: Tue, 25 Mar 2008 07:09:19 -0700 (PDT) [thread overview]
Message-ID: <846433.9019.qm@web36605.mail.mud.yahoo.com> (raw)
In-Reply-To: <200803251523.34329.russell@coker.com.au>
--- Russell Coker <russell@coker.com.au> wrote:
> unstable0:~/coreutils-6.10# ls -l /
> total 158
> drwxr-xr-x+ 2 root root 4096 2008-03-25 10:02 bin
> drwxr-xr-x+ 6 root root 1024 2008-03-21 12:30 boot
> drwxr-xr-x+ 16 root root 3700 2008-03-25 13:38 dev
> drwxr-xr-x+ 80 root root 4096 2008-03-25 13:38 etc
> drwxr-xr-x+ 3 root root 4096 2008-02-15 22:08 home
>
> In Debian/Unstable the output of "ls -l" is as above, the "+" indicates a SE
> Linux security context
The "+" indicates that there is additional security metadata associated
with the file, it could be an ACL, timelock, or just about anything.
This is in accordance with the POSIX P1003.2 specification for ls(1).
> - which doesn't do much good when every file has one.
Well, there is that.
> http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=472590
>
> The above URL has the Debian bug report with a patch.
I honestly don't know if this should be considered a bug in ls.
It is behaving as documented and if you've got MCS turned on
the SELinux label is being used to make DAC decisions. The "+"
is there to let you know that the mode bits don't tell the
whole access control story, but as you say, it is pretty silly
when every file has it.
> If you wish to add additional comments then email sent to
> 472590@bugs.debian.org will be appended.
>
> --
> russell@coker.com.au
> http://etbe.coker.com.au/ My Blog
>
> http://www.coker.com.au/sponsorship.html Sponsoring Free Software development
>
> --
> This message was distributed to subscribers of the selinux mailing list.
> If you no longer wish to subscribe, send mail to majordomo@tycho.nsa.gov with
> the words "unsubscribe selinux" without quotes as the message.
>
>
>
Casey Schaufler
casey@schaufler-ca.com
--
This message was distributed to subscribers of the selinux mailing list.
If you no longer wish to subscribe, send mail to majordomo@tycho.nsa.gov with
the words "unsubscribe selinux" without quotes as the message.
next prev parent reply other threads:[~2008-03-25 14:41 UTC|newest]
Thread overview: 18+ messages / expand[flat|nested] mbox.gz Atom feed top
2008-03-25 4:23 ls in Debian/Unstable Russell Coker
2008-03-25 14:09 ` Casey Schaufler [this message]
2008-03-25 15:08 ` Jim Meyering
2008-03-25 21:22 ` Russell Coker
[not found] ` <20080325173116.GQ2626@mathom.us>
2008-03-25 21:24 ` Bug#472590: " Russell Coker
2008-03-25 21:28 ` Jim Meyering
[not found] ` <20080325234310.GR2626@mathom.us>
2008-03-26 5:12 ` Russell Coker
2008-03-31 9:02 ` Jim Meyering
2008-03-31 9:23 ` Russell Coker
2008-03-31 9:43 ` Jim Meyering
2008-04-02 20:33 ` RFC: changing the "+" in ls -l output to be "." or "+" Jim Meyering
2008-10-23 12:20 ` Jim Meyering
2008-10-24 3:18 ` Vikram Noel Ambrose
2008-10-24 7:04 ` Jim Meyering
2008-10-24 13:19 ` Mike Edenfield
2008-10-26 7:46 ` Russell Coker
2008-10-26 8:09 ` Jim Meyering
2008-10-31 13:37 ` Daniel J Walsh
Reply instructions:
You may reply publicly to this message via plain-text email
using any one of the following methods:
* Save the following mbox file, import it into your mail client,
and reply-to-all from there: mbox
Avoid top-posting and favor interleaved quoting:
https://en.wikipedia.org/wiki/Posting_style#Interleaved_style
* Reply using the --to, --cc, and --in-reply-to
switches of git-send-email(1):
git send-email \
--in-reply-to=846433.9019.qm@web36605.mail.mud.yahoo.com \
--to=casey@schaufler-ca.com \
--cc=jim@meyering.net \
--cc=russell@coker.com.au \
--cc=selinux@tycho.nsa.gov \
/path/to/YOUR_REPLY
https://kernel.org/pub/software/scm/git/docs/git-send-email.html
* If your mail client supports setting the In-Reply-To header
via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line
before the message body.
This is an external index of several public inboxes,
see mirroring instructions on how to clone and mirror
all data and code used by this external index.