Research Menu

.
Skip Search Box

SELinux Mailing List

Re: Proposed policy feature: $1_domain attribute

From: Stephen Smalley <sds_at_tycho.nsa.gov>
Date: Tue, 01 Mar 2005 09:35:48 -0500


On Tue, 2005-03-01 at 08:58 -0500, Ivan Gyurdiev wrote:
> I'd like to mark all role-dependent domains with a new attribute
> $1_domain (analogous to $1_file_type), and then do the following in
> base_user_macros.te:
>
> can_ps($1, $1_domain)
> can_ptrace($1, $1_domain)
>
> Objections?

can_ptrace? You could easily end up allowing unintended permissions directly to the user domain that were previously limited to a specific program.

-- 
Stephen Smalley <sds@tycho.nsa.gov>
National Security Agency


--
This message was distributed to subscribers of the selinux mailing list.
If you no longer wish to subscribe, send mail to majordomo@tycho.nsa.gov with
the words "unsubscribe selinux" without quotes as the message.
Received on Tue 1 Mar 2005 - 09:46:48 EST
 

Date Posted: Jan 15, 2009 | Last Modified: Jan 15, 2009 | Last Reviewed: Jan 15, 2009

 
bottom

National Security Agency / Central Security Service