logo       

Re: glibc post upgrade: msg#00175

Subject: Re: glibc post upgrade
Stephen Smalley wrote:

On Thu, 2004-08-26 at 09:44, Stephen Smalley wrote:
On Thu, 2004-08-26 at 05:37, Jeff Johnson wrote:
Malicious code from untrusted package problem not going to be solved by rpm_script_t alone afaict either.
Right.  We still need a mechanism for distinguishing among packages and
running scriptlets in different domains based on either some property of
the package (the authority that signed it) or some knowledge of the
admin (i.e. he specifies the desired scriptlet domain for all packages
obtained from a given repository in his yum.conf or similar).

Not to mention needing different domains for rpm itself in such
scenarios...

There are a slew of issues beyond the mechanics of exec'ing a helper to establish a new
domain for rpm to run in.

The open questions that I have are:
  a) Can untrusted and trusted data be stored in the same file?
  b) Can trusted packages depend on untrusted? How?
c) How to preserve the existing rpmlib API while re-execing a helper that will require
   non-trivial amounts of state to be reconstructed?

"trust" defined however selinux wishes of course.

Probably easier to write an installer from scratch for selinux purposes than it will be to
try to adapt the existing rpm code base is my current opinion.

73 de Jeff



<Prev in Thread] Current Thread [Next in Thread>
Google Custom Search

Recently Viewed:
linux.arklinux....    user-groups.lin...    kde.usability/2...    ietf.ipp/2002-0...    mail.spam.spamc...    os.netbsd.devel...    audio.cd-record...    text.unicode.de...    php.documentati...    games.fps.halfl...    window-managers...    suse.oracle.gen...    bug-tracking.gn...    video.dvdrip.us...    xfree86.cvs/200...    java.netbeans.m...    network.argus/2...    culture.sf.kill...    debian.ports.al...    freebsd.questio...    qplus.devel/200...    handhelds.palm....   
Home | blog view | USPTO Patent Archive | advertise | OSDir is an inevitable website. super tiny logo

Free Magazines

Cisco News
Receive a free quarterly e-newsletter with exclusive articles on how Cisco IT uses its own products and solutions to enable the business.
subscribe

Systems Management News, the newspaper for IT systems administration and data center managers! Each issue of Systems Management News is chock-full of news and analysis to help you understand what's happening in your field.
subscribe

The Enterprise Newsweekly eWeek is the essential technology information source for builders of e-business.
subscribe

Oracle Magazine Oracle Magazine contains technology strategy articles, sample code, tips, Oracle and partner news, how to articles for developers and DBAs, and more. Oracle (NASDAQ: ORCL) is the world's largest enterprise software company.
subscribe

Total Telecom Total Telecom is "The Economist of the communications industry".
subscribe