From: Jim Meyering <jim@meyering.net>
To: Stephen Smalley <sds@tycho.nsa.gov>
Cc: Karl MacMillan <kmacmillan@mentalrootkit.com>
Cc: selinux@tycho.nsa.gov
Subject: Re: justifying --context=CTX (-Z) for upstream coreutils, like mkdir
Date: Mon, 21 Aug 2006 17:58:58 +0200 [thread overview]
Message-ID: <87wt929j25.fsf@rho.meyering.net> (raw)
In-Reply-To: <1155581090.28766.217.camel@moss-spartans.epoch.ncsc.mil> (Stephen Smalley's message of "Mon, 14 Aug 2006 14:44:50 -0400")
Stephen Smalley <sds@tycho.nsa.gov> wrote:
> On Mon, 2006-08-14 at 19:18 +0200, Jim Meyering wrote:
>> I agree that it's not a trivial way to use programs, but isn't the
>> scenario that'd require such usage a little bit off the beaten track?
>
> I'm not sure that this is a valid assumption. It might be educational
> (or perhaps not) to take your proposal to fedora-selinux-list, and seek
> feedback there, as I think they have a much larger subscriber base and
As you've probably noticed, I posted to the lists, as you suggested:
https://www.redhat.com/archives/fedora-list/2006-August/msg02264.html (long)
I suppose it's still early, but so far, all I have is positive feedback:
http://lists.gnu.org/archive/html/bug-coreutils/2006-08/msg00147.html
Support (and even rebuttal) welcomed.
Even silence is ok, as long as it implies consent :)
> have people who are more representative of ordinary users. Or even
> fedora-list itself, as plenty of people are using Fedora w/SELinux
> without even subscribing to any of the SELinux-specific lists.
>
>> But of course, my whole scenario depends on SELinux
>> making it possible to write a program like fscon.
>
> I'm not convinced that even if SELinux supported such a program that it
> should replace the -Z options in coreutils. I'd see that more as a way
> of applying SELinux to the much larger set of utils, particularly third
> party ones, that are truly not feasible for us to patch.
FYI, I learned of another tool, like the proposed fscon, that performs a
kernel state change just before exec'ing some other program: setarch(8):
$ man setarch
SETARCH(8) Linux Programmer's Manual SETARCH(8)
NAME
setarch - change reported architecture in new program environment
and set personality flags
SYNOPSIS
setarch <arch> [options] [program [arguments]]
arch [options] [program [arguments]]
DESCRIPTION
setarch This utility currently only affects the output of uname
-m. For example, on an AMD64 system, running 'setarch i386 pro-
gram' will cause 'program' to see i686 (or other relevant arch)
instead of x86_64 as machine type. It also allows to set various
personality options.
...
--
This message was distributed to subscribers of the selinux mailing list.
If you no longer wish to subscribe, send mail to majordomo@tycho.nsa.gov with
the words "unsubscribe selinux" without quotes as the message.
next prev parent reply other threads:[~2006-08-21 15:58 UTC|newest]
Thread overview: 32+ messages / expand[flat|nested] mbox.gz Atom feed top
2006-08-11 13:58 justifying --context=CTX (-Z) for upstream coreutils, like mkdir Jim Meyering
2006-08-11 14:58 ` Karl MacMillan
2006-08-11 15:23 ` Stephen Smalley
2006-08-11 15:46 ` Casey Schaufler
2006-08-11 16:45 ` Jim Meyering
2006-08-12 17:43 ` Daniel J Walsh
2006-08-18 10:37 ` install vs. matchpathcon(8) [Re: justifying --context=CTX (-Z) Jim Meyering
2006-08-28 19:14 ` Stephen Smalley
2006-08-14 14:56 ` justifying --context=CTX (-Z) for upstream coreutils, like mkdir Karl MacMillan
2006-08-14 15:53 ` Jim Meyering
2006-08-14 16:02 ` Karl MacMillan
2006-08-14 17:18 ` Jim Meyering
[not found] ` <1155581090.28766.217.camel@moss-spartans.epoch.ncsc.mil>
2006-08-21 15:58 ` Jim Meyering [this message]
2006-08-21 17:40 ` Christopher J. PeBenito
2006-08-21 21:31 ` Jim Meyering
2006-08-22 13:12 ` Joshua Brindle
2006-08-22 16:03 ` Jim Meyering
2006-08-22 16:23 ` Joshua Brindle
2006-08-22 17:16 ` Jim Meyering
2006-08-23 0:27 ` James Antill
2006-08-23 10:43 ` Jim Meyering
2006-08-28 12:23 ` Joshua Brindle
2006-08-28 20:24 ` Stephen Smalley
2006-08-29 19:11 ` Stephen Smalley
2006-08-28 19:05 ` Stephen Smalley
2006-08-23 11:52 ` Joshua Brindle
2006-08-21 17:58 ` Karl MacMillan
2006-08-21 21:15 ` Jim Meyering
2006-08-16 17:05 ` James Antill
2006-08-16 21:18 ` Jim Meyering
2006-08-28 20:00 ` Stephen Smalley
2006-08-28 20:10 ` Stephen Smalley
Reply instructions:
You may reply publicly to this message via plain-text email
using any one of the following methods:
* Save the following mbox file, import it into your mail client,
and reply-to-all from there: mbox
Avoid top-posting and favor interleaved quoting:
https://en.wikipedia.org/wiki/Posting_style#Interleaved_style
* Reply using the --to, --cc, and --in-reply-to
switches of git-send-email(1):
git send-email \
--in-reply-to=87wt929j25.fsf@rho.meyering.net \
--to=jim@meyering.net \
--cc=kmacmillan@mentalrootkit.com \
--cc=sds@tycho.nsa.gov \
/path/to/YOUR_REPLY
https://kernel.org/pub/software/scm/git/docs/git-send-email.html
* If your mail client supports setting the In-Reply-To header
via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line
before the message body.
This is an external index of several public inboxes,
see mirroring instructions on how to clone and mirror
all data and code used by this external index.