[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]

Re: TTY question


On Thu, 2005-02-10 at 16:39, Ivan Gyurdiev wrote:
> Actually here's probably why:
> it's duplicated in su_mini_domain:
> 
> # Close and re-open ttys and ptys to get the fd into the correct domain.
> allow $1_su_t { ttyfile ptyfile }:chr_file { read write };
> 
> So it's all good.

That likely isn't necessary presently, as su/pam_selinux no longer does
that (it caused breakage; we'd have to directly patch su to do it right,
and at that point, we'd likely just introduce a proxy pty).

-- 
Stephen Smalley <sds@xxxxxxxxxxxxxx>
National Security Agency


--
This message was distributed to subscribers of the selinux mailing list.
If you no longer wish to subscribe, send mail to majordomo@xxxxxxxxxxxxx with
the words "unsubscribe selinux" without quotes as the message.


This mailing list archive is a service of Copilot Consulting.