Please take our Survey
logo       

Choosing A Webhost:
A web hosting service is a type of Internet hosting service that allows individuals and organizations to provide their own website accessible via the World Wide Web. Web hosts are companies that provide space on a server they own for use by their clients as well as providing Internet connectivity, typically in a data center. Web hosts can also provide data center space and connectivity to the Internet for servers they do not own to be located in their data center, called colocation. more...

Re: More MCS: msg#00182

Subject: Re: More MCS
On Mon, 2005-10-31 at 14:49 -0500, Gene Czarcinski wrote:
> I tried seting a category on a directory in /tmp and then (with touch) 
> creating a file under that directory.  So far so good.
> 
> I then ssh'ed into the system as another user which does not have those 
> categories defined in seusers.  This user could access the file.  This sounds 
> like a bug to me.

Looks like the MCS constraints (as defined in policy/mcs) only constrain
access to files, not directories, presently (and this is noted in a
comment in that file, so it seems to be intentional).  They do appear to
work correctly for files.  Use of categories on directories doesn't seem
to be supported at present under MCS.

> Also, is there a way that a category value can be propogated to all 
> files/directories below it?

Hmmm...the current MLS logic inherits from the process'
effective/current/low level rather than from the parent directory.

-- 
Stephen Smalley
National Security Agency



<Prev in Thread] Current Thread [Next in Thread>
Google Custom Search

Recently Viewed:
qnx.openqnx.dev...    gcc.libstdc++.c...    solaris.opensol...    information-ret...    misc.misterhous...    web.catalyst.ge...    apache.webservi...    redhat.release....    hardware.lirc/2...    kernel.autofs/2...    technology.sust...    linux.vdr/2003-...    editors.lyx.gen...    org.user-groups...    netbsd.devel.pk...    xdg.devel/2004-...    version-control...    jakarta.slide.d...    debian.packages...    creativecommons...    ports.ppc.embed...    bug-tracking.bu...   
Home | blog view | USPTO Patent Archive | advertise | OSDir is an inevitable website. super tiny logo

Free Magazines

Cisco News
Receive a free quarterly e-newsletter with exclusive articles on how Cisco IT uses its own products and solutions to enable the business.
subscribe

Systems Management News, the newspaper for IT systems administration and data center managers! Each issue of Systems Management News is chock-full of news and analysis to help you understand what's happening in your field.
subscribe

The Enterprise Newsweekly eWeek is the essential technology information source for builders of e-business.
subscribe

Oracle Magazine Oracle Magazine contains technology strategy articles, sample code, tips, Oracle and partner news, how to articles for developers and DBAs, and more. Oracle (NASDAQ: ORCL) is the world's largest enterprise software company.
subscribe

Total Telecom Total Telecom is "The Economist of the communications industry".
subscribe