[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]
Re: TTY question
On Thu, 2005-02-10 at 14:15, Ivan Gyurdiev wrote:
> Does this look reasonable?
- The patch removes a rule giving $1_su_t certain permissions to sysadm
tty/pty types, likely requires testing to verify that this doesn't
present a problem for proper handling and subsequent restoration of the
label when the su'd shell exits.
- It might be desirable to reduce the permissions allowed by the macro
from rw_file_perms to just { read write getattr }, as I see that many
domains were only being given those permissions previously. Likewise,
might want to reduce r_dir_perms down to just { read search getattr }.
Otherwise, looks sane to me (subject to testing, of course).
--
Stephen Smalley <sds@xxxxxxxxxxxxxx>
National Security Agency
--
This message was distributed to subscribers of the selinux mailing list.
If you no longer wish to subscribe, send mail to majordomo@xxxxxxxxxxxxx with
the words "unsubscribe selinux" without quotes as the message.
This mailing list archive is a service of Copilot Consulting.