david@lang.hm wrote:Nit: SELinux figures out what to label new files fine, just not based on the name. This works in most cases, eg., when user_t creates a file in /tmp it becomes user_tmp_t, incidentally this is something that AA cannot handle, if the filenames aren't normalized (they normally aren't). For example, my ssh agent socket is stored in /tmp/ssh-XXXXXXXX, where the X's are random characters, AA can't differentiate admin ssh agents from unprivileged user ssh agents, showing a serious flaw in their model. The complaint is that name-based labeling doesn't currently exist (and as Sean has stated that doesn't mean it _can't_ exist, just that it doesn't currently). In practice this has not been as big of an issue as you are making it out to be. Granted restorecond has a tiny race, and I wouldn't recommend using it on very security sensitive files but for usability having it relabel user_home_t to user_http_content_t isn't a problem (and causes no security issues). -
| Eric Anholt | [PATCH] Export kmap_atomic_pfn for DRM-GEM. |
| Rafael J. Wysocki | 2.6.27-rc4-git1: Reported regressions from 2.6.26 |
| Robin Lee Powell | NFS hang + umount -f: better behaviour requested. |
| Avi Kivity | [PATCH] x86: default to reboot via ACPI |
git: | |
| Shawn O. Pearce | Re: MinGW port - initial work uploaded |
| Pierre Habouzit | git submodules |
| Mike Hommey | Re: Minor annoyance with git push |
| H. Peter Anvin | kde.git is now online |
| Chris Bullock | OpenBSD isakmpd and pf vs Cisco PIX or ASA |
| Brandon Lee | Re: DELL PERC 5iR slow performance |
| peter | ntpd not synching |
| bofh | Re: Load balancing with DSR |
| Jim Winstead Jr. | Re: Root Disk/Book Disk Compatibility |
| Peter Grehan | TCP SYN_RECV state: stuck forever in accept() ? |
| Brandon S. Allbery | Re: mkdir says "no space left on device" and more problems... |
| Theodore Ts'o | Re: Stabilizing Linux |
