Research
.
Skip Search Box

SELinux Mailing List

Re: dynamic context transitions

From: Stephen Smalley <sds_at_epoch.ncsc.mil>
Date: Fri, 05 Nov 2004 11:44:45 -0500


On Fri, 2004-11-05 at 11:29, Luke Kenneth Casson Leighton wrote:
> however, are there already asserts covering domain_auto_trans?
>
> the same logic would apply, yes?

The same logic is "Write your policy carefully, and check it well (using assertions, apol, etc.)" It isn't to hardcode a specific logic in the kernel mechanism. Consider unconfined_domain() and the targeted policy; should the kernel mechanism have prohibited the creation of policies that include it?

-- 
Stephen Smalley <sds@epoch.ncsc.mil>
National Security Agency


--
This message was distributed to subscribers of the selinux mailing list.
If you no longer wish to subscribe, send mail to majordomo@tycho.nsa.gov with
the words "unsubscribe selinux" without quotes as the message.
Received on Fri 5 Nov 2004 - 11:49:22 EST
 

Date Posted: Jan 15, 2009 | Last Modified: Jan 15, 2009 | Last Reviewed: Jan 15, 2009

 
bottom

National Security Agency / Central Security Service