Security Enhanced Linux
What's New
Frequently Asked Questions
Background
Documents
License
Download
Participating
Mail List
Archives
Remaining Work
Contributors
Related Work
Press Releases
Information Assurance Research
NIARL In-house Research Areas
Mathematical Sciences Program
Sabbaticals
Computer & Information Sciences Research
Technology Transfer
Advanced Computing
Advanced Mathematics
Communications & Networking
Information Processing
Microelectronics
Other Technologies
Technology Fact Sheets
Publications
Related Links
|
SELinux Mailing ListRe: fork and security context transitions
From: Russell Coker <russell_at_coker.com.au>
Date: Wed, 4 Feb 2004 00:19:11 +1100
For Samba this will not work. The SMB protocol supports multiple SMB identities on the same SMB connection. Currently this is only really used in Windows Terminal Server edition, but it should be used in future workstation products when some bugs in the MS client code are fixed. Because of this such code that you might write for Samba will only work for a while (until the next release of Windows maybe). Of course in the development version of Samba things are a bit different and you can write plug-ins to do these sorts of things. It would be possible to have the main Samba process execute helper programs to do the actual file IO and then communicate with the parent process by shared memory and pipes. Then a smbd which is serving for two SMB identities can have two helper children running in different contexts. The other option is something like setfsuid() for SE Linux as previously discussed. -- http://www.coker.com.au/selinux/ My NSA Security Enhanced Linux packages http://www.coker.com.au/bonnie++/ Bonnie++ hard drive benchmark http://www.coker.com.au/postal/ Postal SMTP/POP benchmark http://www.coker.com.au/~russell/ My home page -- This message was distributed to subscribers of the selinux mailing list. If you no longer wish to subscribe, send mail to majordomo@tycho.nsa.gov with the words "unsubscribe selinux" without quotes as the message.Received on Tue 3 Feb 2004 - 08:20:54 EST |
|
Date Posted: Jan 15, 2009 | Last Modified: Jan 15, 2009 | Last Reviewed: Jan 15, 2009 |