Research
Skip Research Menus
Research MenuSecurity Enhanced Linux What's New Frequently Asked Questions Background Documents License Download Participating Mail List Archives Remaining Work Contributors Related Work Press Releases Information Assurance Research NIARL In-house Research Areas Mathematical Sciences Program Sabbaticals Computer & Information Sciences Research Technology Transfer Advanced Computing Advanced Mathematics Communications & Networking Information Processing Microelectronics Other Technologies Technology Fact Sheets Publications Related Links |
SELinux Mailing List[patch] Improved D-BUS SELinux mediation
From: Colin Walters <walters_at_verbum.org>
Date: Thu, 11 Nov 2004 00:39:31 -0500
The attached patch improves on the previous patch sent to the D-BUS list for also having D-BUS check service labels for the send_msg permission. One problem I ran into is that send_msg also mediates reply messages; so in order to have a domain just reply to a sent message, it needs the general send_msg back to the sender domain, as well as the service domain. The solution is to add a separate "reply" access vector. D-BUS will check that permission if a message is in reply to a known sent message, otherwise it will use "send_msg". While I was changing the access vectors, I thought I would go ahead and add an "activate_svc" vector too (and add the requisite check in the DBUS code). The long term plan I think is to use D-BUS for system service activation too, and it seems undesirable for e.g. CUPS to have the permission to activate your mail server (which could have other side effects like binding to ports, etc). The patch to D-BUS is first, and the patch to the Flask access_vectors follows. I'll be working on a patch to update the policy itself to handle these new changes soon, along with labeling all the services we currently use.
-- This message was distributed to subscribers of the selinux mailing list. If you no longer wish to subscribe, send mail to majordomo@tycho.nsa.gov with the words "unsubscribe selinux" without quotes as the message.Received on Thu 11 Nov 2004 - 00:39:43 EST |
|
Date Posted: Jan 15, 2009 | Last Modified: Jan 15, 2009 | Last Reviewed: Jan 15, 2009 |