Re: SELinuxDenyPtrace: Write, compile, run, but don't debug applications?

[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]

 



Antonio Trande wrote:
> Maybe if deny_ptrace remains turn on by default already from F17 is good,
> i think.

No, keeping it off also in future releases is what "is good".

> Because of two reasons primarily:
> 
> - Many "Fedora normal users" still don't know because SELinux is
> important, you image  if someone be worried how to turn on a its boolean.

So you want to show Fedora users that SELinux is important by breaking the 
crash reporting tools they use? That'll just tell them to disable SELinux 
altogether (which is what I'll tell them to do if they come complaining to 
#fedora-kde that DrKonqi does not work).

> - If this feature is turned off by default, less feedbacks will come back
> from comunity.

We already have enough feedback to know that the feature fundamentally does 
not work.

        Kevin Kofler

-- 
devel mailing list
devel@xxxxxxxxxxxxxxxxxxxxxxx
https://admin.fedoraproject.org/mailman/listinfo/devel



[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]
[Index of Archives]     [Fedora Announce]     [Fedora Kernel]     [Fedora Testing]     [Fedora Formulas]     [Fedora PHP Devel]     [Kernel Development]     [Fedora Legacy]     [Fedora Maintainers]     [Fedora Desktop]     [PAM]     [Red Hat Development]     [Gimp]     [Yosemite News]
  Powered by Linux