Re: SELinuxDenyPtrace: Write, compile, run, but don't debug applications?

[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]

 



On Wed, 11 Apr 2012, Kalev Lember wrote:

This is the reason why I find it important to make the life as good as
possible for the power users / developers / enthusiasts: when the they
like using Fedora and developing software with Fedora, they're likely to
also invite other people to try Fedora out. Which means more users, more
developers, more people to spread the word.

While true, it is totally irrelevant to this discussion. I might as well
say that SElinux is responsible for Fedora being a distribution without
viruses and malware, unlike windows and mac, and so it is exactly the
additional security and lack of anti-malware tools bringing your
computer to a grinding halt that is the success of fedora you list
above.

When i was debugging why "passwd" was segfaulting, I installed gdb and
guess what, it denied me ptrace, as it should! However, it even told me
within gdb what to type to change the selinux boolean to continue with
the gdb session, no different then gdb telling you how and which debuginfo
packages to install.

Once the automatic debugger helpers are working, I really hope ptrace
will be denied again per default, as it would be a very workable good
useful security addition to the system.

Paul
--
devel mailing list
devel@xxxxxxxxxxxxxxxxxxxxxxx
https://admin.fedoraproject.org/mailman/listinfo/devel



[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]
[Index of Archives]     [Fedora Announce]     [Fedora Kernel]     [Fedora Testing]     [Fedora Formulas]     [Fedora PHP Devel]     [Kernel Development]     [Fedora Legacy]     [Fedora Maintainers]     [Fedora Desktop]     [PAM]     [Red Hat Development]     [Gimp]     [Yosemite News]
  Powered by Linux