On Sat, Mar 20, 2004 at 10:19:41AM +0100, Ronny Buchmann wrote: > > with the fact that scsi level command access allows you to do stuff like > > 'erase firmware', which normally suggests root only is good ) > Shouldn't setuid root cdrecord be safe with SELinux? Only if it is written properly. The problem doesnt go away unless you move most of CD burning into the kernel. At which point of course its just as likely to be wrong in the kernel...