[Date Prev][Date Next] [Thread Prev][Thread Next]
[Thread Index]
[Date Index]
[Author Index]
Re: Please disable the SELinux execstack/relro checks before FC5 final
- From: Arjan van de Ven <arjan fenrus demon nl>
- To: Development discussions related to Fedora Core <fedora-devel-list redhat com>
- Cc: dwalsh redhat com
- Subject: Re: Please disable the SELinux execstack/relro checks before FC5 final
- Date: Fri, 17 Feb 2006 21:14:29 +0100
> Another question is what domains are in view here, e.g. all domains
> (such that allow_execstack permits execstack to every process rather
> than just unconfined processes) or just unconfined_t (so that confined
> daemons remain protected even if allow_execstack is enabled)?
right now I fear the only sane answer is "set all to permissive
behavior"; the minimum for fc5 would be everything that can do plugins
of any kind, or uses libraries that tend to get replaced (3D ones ;).
But that ends up being a whole whopping lot...
I really wish the user notification/config thing existed, but that will
take time to get right for sure...
[Date Prev][Date Next] [Thread Prev][Thread Next]
[Thread Index]
[Date Index]
[Author Index]