Research
.
Skip Search Box

SELinux Mailing List

Re: mysql policy

From: Tom <tom_at_lemuria.org>
Date: Wed, 30 Oct 2002 10:35:22 +0100


What is the best-practice on labelling script files? Should they be treated with more care than binaries?

I'm asking because I have largely tossed Russell's mysqld domain and started a new one from scratch, not because Russell's was in any way bad but because doing so allows me to better understand what is happening and what permissions it needs. This way I found out that the wrapper (safe_mysqld) that the init script uses to start mysqld requires some more and other permissions than the daemon itself, so I'm thinking about putting it into a different domain so that the daemon, once running, doesn't have all those unneeded priviledges.

safe_mysqld is a shell script. I can't see a problem with that from the pure "hacking" perspective (modifying a shell script is not that much easier than modifying a binary), but maybe its reliance on /bin/sh makes it a different game?

--

PGP/GPG key: http://web.lemuria.org/pubkey.html pub 1024D/2D7A04F5 2002-05-16 Tom Vogt <tom@lemuria.org>

     Key fingerprint = C731 64D1 4BCF 4C20 48A4 29B2 BF01 9FA1 2D7A 04F5

--

This message was distributed to subscribers of the selinux mailing list. If you no longer wish to subscribe, send mail to majordomo@tycho.nsa.gov with the words "unsubscribe selinux" without quotes as the message. Received on Wed 30 Oct 2002 - 04:54:38 EST

 

Date Posted: Jan 15, 2009 | Last Modified: Jan 15, 2009 | Last Reviewed: Jan 15, 2009

 
bottom

National Security Agency / Central Security Service