On Thu, 2007-06-21 at 21:54 +0200, Lars Marowsky-Bree wrote:
Or can access the data under a different path to which their profile
does give them access, whether in its final destination or in some
temporary file processed along the way.
The incomplete mediation flows from the design, since the pathname-based
mediation doesn't generalize to cover all objects unlike label- or
attribute-based mediation. And the "use the natural abstraction for
each object type" approach likewise doesn't yield any general model or
anything that you can analyze systematically for data flow.
The emphasis on never modifying applications for security in AA likewise
has an adverse impact here, as you will ultimately have to deal with
application mediation of access to their own objects and operations not
directly visible to the kernel (as we have already done in SELinux for
D-BUS and others and are doing for X). Otherwise, your "protection" of
desktop applications is easily subverted.
Um, no. It might not be able to directly open files via that path, but
showing that it can never read or write your mail is a rather different
matter.
--
Stephen Smalley
National Security Agency
-