linux-audit.redhat.com archive mirror
 help / color / mirror / Atom feed
* inotify_rm_watch behavior
@ 2006-09-11 18:05 Eduardo Madeira Fleury
  2006-09-11 18:48 ` Stephen Smalley
  2006-09-11 18:49 ` Amy Griffis
  0 siblings, 2 replies; 8+ messages in thread
From: Eduardo Madeira Fleury @ 2006-09-11 18:05 UTC (permalink / raw)
  To: linux-audit

Hey all,

I'm doing some tests and currently inotify_rm_watch is not performing any 
permission checks, i.e., an ordinary user can remove a watch set by root on a 
file with root:root 400 permission.

Is this the expected behavior? Seems like neither MAC nor MLS checks are being 
done.

Regards,
-- 
Eduardo M. Fleury
IBM Linux Technology Center Brazil
Mobile: +55-19-81224410
email/sametime: efleury@br.ibm.com

^ permalink raw reply	[flat|nested] 8+ messages in thread

end of thread, other threads:[~2006-09-12 14:10 UTC | newest]

Thread overview: 8+ messages (download: mbox.gz follow: Atom feed
-- links below jump to the message on this page --
2006-09-11 18:05 inotify_rm_watch behavior Eduardo Madeira Fleury
2006-09-11 18:48 ` Stephen Smalley
2006-09-11 18:49 ` Amy Griffis
2006-09-11 19:15   ` Stephen Smalley
2006-09-11 19:34     ` Amy Griffis
2006-09-12 13:45       ` Stephen Smalley
2006-09-12 14:09         ` [redhat-lspp] " Darrel Goeddel
2006-09-12 14:10         ` Stephen Smalley

This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox;
as well as URLs for NNTP newsgroup(s).