Re: in defense of SELinux
Daira Hopwood <[email protected]>
| Newsgroups | gmane.comp.capabilities.general |
|---|---|
| Message-ID | <[email protected]> |
On 17/10/13 01:59, Jonathan S. Shapiro wrote: > There are four ways in which SELinux /isn't/ capturable with an ocap policy. (I dispute the other three ways as well, but this is the one I wanted to comment on:) > The third is that SELinux is robust in the presence of certain administrative > issues. Example: we may intend for (e.g.) the web server to be able to write a particular > log file, but for administrative reasons we may want to delete the old log file and create > a new one in its place. In a strict ocap model that's doable in theory but inconvenient in > practice. It's straightforward, no? The application has a logging capability and does not care about the details of how logging is done. This is instantiated with a cap to a logger object that is able to rotate log files as necessary. > In fact, if you added the required indirection on every file-like object, you'd > find that the statically traced authority of every application had become effectively > infinite. But in a cap system, you clearly don't need to do that. -- Daira Hopwood ⚥ _______________________________________________ cap-talk mailing list [email protected] http://www.eros-os.org/mailman/listinfo/cap-talk
signature.asc
(application/pgp-signature, 555 B)
-----BEGIN PGP SIGNATURE----- Version: GnuPG v1.4.12 (GNU/Linux) Comment: Using GnuPG with Thunderbird - http://www.enigmail.net/ iQEcBAEBAgAGBQJSY+gjAAoJEAZ/SSCYzydiN0IH+wddVUUdo0AHGGkJaQgU1oV5 UleWuk1Mu//HmQ5ST2JJEo4lI6Kwnk5smGUhEihdk+CVEY0YcvFiWcrahAdGy6MF nJ7aGzQG3GrGHVe9X//ZOBka7XZFV/f2F0wbhA4lREOs7fWINu+QVcw0BWODOHFY StbvZsMFHy0g+u2VG8hS99AfTlUk4l+OPwR6wv4Ou1CQhGBiTIwfCMEF5gp/VVBW nmf4HG+XsaxxX1i4gIF0OIfVburk+CbQbEGJt5A0eQlV5yWvayp0EkrYjGHKCjL0 6jTRcT38SeuORYk9Wq2sXwFesZLJQtNVjBRKQbJ4CjXiYX7qUgtgRAI8UtlG4OM= =Dv6v -----END PGP SIGNATURE-----