3 ms·
One could envision a scenario where much of that custom wiring could be auto-generated somehow (e.g.: with some kind of defaults + dynamic analysis). But the p
by drvdevd 10y ago
One could envision a scenario where much of that custom wiring could be auto-generated somehow (e.g.: with some kind of defaults + dynamic analysis).
But the point is really - this is a distro issue and SELinux is a building block. If your distro is using SELinux and it's causing you no end of headaches consider that it may be your distro that's the problem...
- e12e 10y agoHm. Maybe add behavior tests to packages and run those in order to generate simplistic selinux policies? Then expand to "negative" behavioral tests (from letting httpd write to /var/log/access.log to checking that it can't write to auth.log etc)?
- drvdevd 10y agoYeah I suppose it's not really tractable to automatically infer the total behavior of a program (halting problem?)... I had some kind of weird strace like mechanism in mind.. Perhaps static analysis to see which library functions are linked in the package (require symbols in all binaries) and then having a set of default policies per-package based on those (including like you said, "this program never calls X, is not in category Y, therefore it doesn't need to be able to write to /path/to/Z" and so on).. I dunno. Ideas