Research
.
Skip Search Box

SELinux Mailing List

Re: Sepcut Relabel problem

From: Russell Coker <russell_at_coker.com.au>
Date: Tue, 13 Apr 2004 00:00:39 +1000


On Thu, 8 Apr 2004 02:17, David Caplan <dac@tresys.com> wrote:
> The "rm" line appears to have been added relatively recently to the
> relabel target.  My guess is that the rationale was that many of the
> files in /tmp were no longer labeled correctly after a relabel because
> most of them would have been created via a file transition rule (and
> thus a relabel would change them all to incorrect/default labels, most
> likely denying access to the files anyway if the system were in
> enforcing mode).

Your guess is correct. Correctly labelling all the files in /tmp is virtually impossible. Leaving existing entries in /tmp as file_t does not work as many programs use fixed file names (of course that's usually a bad idea, but that's another discussion) and won't work if the file names exist and can't be unlinked.

There are two solutions to this problem, one is to have your system clean /tmp on reboot (as is done in Debian). The other is to have a relabel clean out /tmp.

-- 
http://www.coker.com.au/selinux/   My NSA Security Enhanced Linux packages
http://www.coker.com.au/bonnie++/  Bonnie++ hard drive benchmark
http://www.coker.com.au/postal/    Postal SMTP/POP benchmark
http://www.coker.com.au/~russell/  My home page


--
This message was distributed to subscribers of the selinux mailing list.
If you no longer wish to subscribe, send mail to majordomo@tycho.nsa.gov with
the words "unsubscribe selinux" without quotes as the message.
Received on Mon 12 Apr 2004 - 10:02:12 EDT
 

Date Posted: Jan 15, 2009 | Last Modified: Jan 15, 2009 | Last Reviewed: Jan 15, 2009

 
bottom

National Security Agency / Central Security Service