RE: user guide draft: "Targeted Policy" review

[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]

 




> -----Original Message-----
> From: owner-selinux@xxxxxxxxxxxxx [mailto:owner-selinux@xxxxxxxxxxxxx]
On
> Behalf Of Dominick Grift
> Sent: Wednesday, September 03, 2008 2:25 AM
> To: Murray McAllister
> Cc: SE Linux
> Subject: Re: user guide draft: "Targeted Policy" review
> 
> On Wed, 2008-09-03 at 17:41 +1000, Murray McAllister wrote:
> > Hi,
> 
> > Are there any SELinux restrictions on what users can do when they
run
> > unconfined?
> 
> Yes i think unconfined users cannot do execmem, execstack, execheap by
> default.
> Otherwise they're exempted from policy enforcement i think.

In RHEL5, constraints still apply to applications running in the
unconfined_t domain, so all the MLS constraints apply. I'm not familiar
with Fedora 10, so it may be different.

> 
> --
> Dominick Grift <domg472@xxxxxxxxx>



--
This message was distributed to subscribers of the selinux mailing list.
If you no longer wish to subscribe, send mail to majordomo@xxxxxxxxxxxxx with
the words "unsubscribe selinux" without quotes as the message.

[Index of Archives]     [Selinux Refpolicy]     [Linux SGX]     [Fedora Users]     [Fedora Desktop]     [Yosemite Photos]     [Yosemite Camping]     [Yosemite Campsites]     [KDE Users]     [Gnome Users]

  Powered by Linux