Research
.
Skip Search Box

SELinux Mailing List

Re: [PATCH] SELinux: new /proc/self/attr/ipccreate for explicite ipc object labeling

From: Stephen Smalley <stephen.smalley_at_gmail.com>
Date: Tue, 18 Jul 2006 16:05:11 -0400


On 7/18/06, Eric Paris <eparis@parisplace.org> wrote:
> At this point in time IPC objects (semaphores, message queues, etc) were
> labeled with the label of the process which created them. This patch
> introduces a new /proc/self/attr/ipccreate which will allow a program to
> set the label on ipc objects it is about to create. This may be useful
> in future trusted applications but at this time I do not know of any
> application which needs this functionality, but it should allow better
> more understandable policy to control access to ipc objects.
>
> In security/selinux/include/av_permissions.h the patch also adds a blank
> line at the end. This was the output after the change to the
> access_vectors in policy and I did not edit that file by hand.

In that case, we should fix the script.

--
This message was distributed to subscribers of the selinux mailing list.
If you no longer wish to subscribe, send mail to majordomo@tycho.nsa.gov with
the words "unsubscribe selinux" without quotes as the message.
Received on Tue 18 Jul 2006 - 16:05:18 EDT
 

Date Posted: Jan 15, 2009 | Last Modified: Jan 15, 2009 | Last Reviewed: Jan 15, 2009

 
bottom

National Security Agency / Central Security Service