Research
.
Skip Search Box

SELinux Mailing List

Re: [ANN] SELinux kernel project page

From: Serge E. Hallyn <serue_at_us.ibm.com>
Date: Fri, 11 May 2007 17:54:47 -0500


Quoting James Morris (jmorris@namei.org):
> FYI,
>
> If you're involved in any kind of SELinux kernel development, you may be
> interested in the recently created wiki page:
>
> http://selinuxproject.org/page/Kernel_Development

one item is

  • Support for kernel namespaces

Did anyone have some idea of what we might want to add? My thought was that the policy server work would pretty much cover the desired extensions - so I create a type called 'vserver1', and give vserver1.admin the rights to create subtypes of vserver1 and administer it's policy, subject to vserver1's rights.

Maybe someone wanted to add object types for each namespace type, with 'unshare', 'view', and perhaps (though unlikely) 'enter' permissions?

Finally checkpointing seems safely covered by ptrace, and kill by, well, kill...

-serge

> This is where we'll be keeping track of todo items and various kernel
> related issues.
>
> Please feel free to edit the page yourself (wiki accounts may be obtained
> by emailing Karl MacMillan <kmacmill@redhat.com>).
>
> At some point, we may migrate this to a Trac system, although that may be
> something to consider more widely for the SELinux project in general.
>
>
> - James
> --
> James Morris
> <jmorris@namei.org>
>
> --
> This message was distributed to subscribers of the selinux mailing list.
> If you no longer wish to subscribe, send mail to majordomo@tycho.nsa.gov with
> the words "unsubscribe selinux" without quotes as the message.

--
This message was distributed to subscribers of the selinux mailing list.
If you no longer wish to subscribe, send mail to majordomo@tycho.nsa.gov with
the words "unsubscribe selinux" without quotes as the message.
Received on Fri 11 May 2007 - 18:54:51 EDT
 

Date Posted: Jan 15, 2009 | Last Modified: Jan 15, 2009 | Last Reviewed: Jan 15, 2009

 
bottom

National Security Agency / Central Security Service