Research
.
Skip Search Box

SELinux Mailing List

Re: Updated policy

From: Stephen Smalley <sds_at_epoch.ncsc.mil>
Date: Thu, 27 Jan 2005 10:50:36 -0500


On Wed, 2005-01-26 at 03:22, Ivan Gyurdiev wrote:
> On Tue, 2005-01-25 at 14:56 -0500, Daniel J Walsh wrote:
> > Many changes to allow policy to support telnetd, rlogind and rshd.
> >
> > allow mount_t binfmt_misc_fs_t:dir mounton;
> > Required to run wine.
>
> Now there is:
>
> allow mount_t binfmt_misc_fs_t:dir mounton;
> ...
> # mount binfmt_misc on /proc/sys/fs/binfmt_misc
> allow mount_t sysctl_t:dir { mounton search };
>
> Are both of those necessary?

Shouldn't be. mounton permission is required to the mount point directory, which should be sysctl_t. binfmt_misc_fs_t should only be on the mounted directory. Duplicate mount?

-- 
Stephen Smalley <sds@epoch.ncsc.mil>
National Security Agency


--
This message was distributed to subscribers of the selinux mailing list.
If you no longer wish to subscribe, send mail to majordomo@tycho.nsa.gov with
the words "unsubscribe selinux" without quotes as the message.
Received on Thu 27 Jan 2005 - 10:57:01 EST
 

Date Posted: Jan 15, 2009 | Last Modified: Jan 15, 2009 | Last Reviewed: Jan 15, 2009

 
bottom

National Security Agency / Central Security Service