Please take our Survey
logo       

Choosing A Webhost:
A web hosting service is a type of Internet hosting service that allows individuals and organizations to provide their own website accessible via the World Wide Web. Web hosts are companies that provide space on a server they own for use by their clients as well as providing Internet connectivity, typically in a data center. Web hosts can also provide data center space and connectivity to the Internet for servers they do not own to be located in their data center, called colocation. more...

Re: [patch] CUPS 1.2 SELinux policy changes...: msg#00082

Subject: Re: [patch] CUPS 1.2 SELinux policy changes...
Russell Coker wrote:
On Saturday 12 November 2005 02:47, Michael Sweet <mike@xxxxxxxxxx> wrote:
I removed the non-CUPS rules because the mix of software makes
debugging and validating the CUPS policies that much harder, and it
makes sense to maintain the policies for separate projects
separately...

Firstly, please test your patches first. There is no name_connect access in the unix_stream_socket class or a seteuid capability.

Sorry, I had tested the file context changes but not the rest (still
getting my feet wet).  I mainly wanted to a) alert folks to a problem
with the current policy and b) get feedback.

Please don't remove comments such as "this is not ideal, and allowing setattr access to cupsd_etc_t is wrong". That's a design flaw in cupsd, eventually we want to fix it. Removing the comment decreases the chance of such a design flaw ever being corrected.

Well, given that the comment does not describe the "design flaw" in
enough detail to be useful, and that no one has posted this "design
flaw" to any of the CUPS forums or the STR page on the CUPS site, it
seemed like I was removing a comment that was confusing and
uninformative.

What is the design flaw?

The hplip and ptal policies are OK in the same file as cups. They are printer-specific programs. Having separate lpd and cups files is more of a problem. As we seem to be moving away from the traditional lpd we will probably change things in this regard.

When there is policy involving access between initrc_t and the domains/types defined in a daemon policy file then this belongs in the policy file for the daemon. Important files such as initrc.te should not have sections for all the many daemons that need to interact with them.

Fair enough.  Can we at least segment the rules in each of the files
so that it is clear which rules apply to which sub-programs?

--
______________________________________________________________________
Michael Sweet, Easy Software Products           mike at easysw dot com
Internet Printing and Publishing Software        http://www.easysw.com



<Prev in Thread] Current Thread [Next in Thread>
Google Custom Search

Recently Viewed:
qnx.openqnx.dev...    gcc.libstdc++.c...    solaris.opensol...    information-ret...    misc.misterhous...    web.catalyst.ge...    apache.webservi...    redhat.release....    hardware.lirc/2...    kernel.autofs/2...    technology.sust...    linux.vdr/2003-...    editors.lyx.gen...    org.user-groups...    netbsd.devel.pk...    xdg.devel/2004-...    version-control...    jakarta.slide.d...    debian.packages...    creativecommons...    ports.ppc.embed...    bug-tracking.bu...   
Home | blog view | USPTO Patent Archive | advertise | OSDir is an inevitable website. super tiny logo

Free Magazines

Cisco News
Receive a free quarterly e-newsletter with exclusive articles on how Cisco IT uses its own products and solutions to enable the business.
subscribe

Systems Management News, the newspaper for IT systems administration and data center managers! Each issue of Systems Management News is chock-full of news and analysis to help you understand what's happening in your field.
subscribe

The Enterprise Newsweekly eWeek is the essential technology information source for builders of e-business.
subscribe

Oracle Magazine Oracle Magazine contains technology strategy articles, sample code, tips, Oracle and partner news, how to articles for developers and DBAs, and more. Oracle (NASDAQ: ORCL) is the world's largest enterprise software company.
subscribe

Total Telecom Total Telecom is "The Economist of the communications industry".
subscribe