[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]
Re: TTY question
On Thu, 2005-02-10 at 16:39, Ivan Gyurdiev wrote:
> Actually here's probably why:
> it's duplicated in su_mini_domain:
>
> # Close and re-open ttys and ptys to get the fd into the correct domain.
> allow $1_su_t { ttyfile ptyfile }:chr_file { read write };
>
> So it's all good.
That likely isn't necessary presently, as su/pam_selinux no longer does
that (it caused breakage; we'd have to directly patch su to do it right,
and at that point, we'd likely just introduce a proxy pty).
--
Stephen Smalley <sds@xxxxxxxxxxxxxx>
National Security Agency
--
This message was distributed to subscribers of the selinux mailing list.
If you no longer wish to subscribe, send mail to majordomo@xxxxxxxxxxxxx with
the words "unsubscribe selinux" without quotes as the message.
This mailing list archive is a service of Copilot Consulting.