Groups | Search | Server Info | Keyboard shortcuts | Login | Register [http] [https] [nntp] [nntps]


Groups > linux.debian.kernel > #57420

Re: CONFIG_SECURITY_SELINUX_CHECKREQPROT_VALUE

From Ben Hutchings <ben@decadent.org.uk>
Newsgroups linux.debian.kernel
Subject Re: CONFIG_SECURITY_SELINUX_CHECKREQPROT_VALUE
Date 2017-04-02 15:50 +0200
Message-ID <trO3f-16F-13@gated-at.bofh.it> (permalink)
References (5 earlier) <trN7b-w5-15@gated-at.bofh.it> <trN7b-w5-17@gated-at.bofh.it> <trN7b-w5-19@gated-at.bofh.it> <trN7b-w5-21@gated-at.bofh.it> <trN7b-w5-5@gated-at.bofh.it>
Organization linux.* mail to news gateway

Show all headers | View raw


[Multipart message — attachments visible in raw view] - view raw

On Sun, 2017-04-02 at 14:35 +0200, Laurent Bigonville wrote:
> Le 02/04/17 à 03:25, cgzones a écrit :
> > Is there any reason why the standard Debian kernel sets the value for 
> > checkreqprot to 1, while the default[1] is 0?

The default is 1.  The commit changing the default to 0 went into
4.11-rc4, i.e. it is not even in an upstream stable release yet.

> > RedHat[2] seems also to use 0 and from the documentation 0 seems to be 
> > the stricter setting.
> > 
> 
> To be honest I've no idea and the RH bug seems to miss some messages and 
> refers to other private bug(s) but I can confirm that on centos 7.3 the 
> value is set to 0.
> 
> The kernel configuration is done by the kernel team, I'm forwarding your 
> question to them on their ML. Maybe they didn't saw the default value 
> has changed?
> 
> Dear kernel maintainer, do you have an idea about this?

It's been that way in Debian since at least 2005.  So anyone who has a
working SELinux policy for Debian must have taken this behaviour into
account.

Maybe we'll go with the new default for buster.

Ben.

-- 
Ben Hutchings
It is impossible to make anything foolproof because fools are so
ingenious.

Back to linux.debian.kernel | Previous | NextPrevious in thread | Next in thread | Find similar | Unroll thread


Thread

Re: CONFIG_SECURITY_SELINUX_CHECKREQPROT_VALUE Laurent Bigonville <bigon@debian.org> - 2017-04-02 14:50 +0200
  Re: CONFIG_SECURITY_SELINUX_CHECKREQPROT_VALUE Ben Hutchings <ben@decadent.org.uk> - 2017-04-02 15:50 +0200
    Re: CONFIG_SECURITY_SELINUX_CHECKREQPROT_VALUE cgzones <cgzones@googlemail.com> - 2017-04-02 16:50 +0200
      Re: CONFIG_SECURITY_SELINUX_CHECKREQPROT_VALUE Ben Hutchings <ben@decadent.org.uk> - 2017-04-02 21:30 +0200
        Re: CONFIG_SECURITY_SELINUX_CHECKREQPROT_VALUE Christian Göttsche <cgzones@googlemail.com> - 2017-04-11 17:00 +0200
          Re: CONFIG_SECURITY_SELINUX_CHECKREQPROT_VALUE Laurent Bigonville <bigon@debian.org> - 2017-04-11 17:20 +0200
            Re: CONFIG_SECURITY_SELINUX_CHECKREQPROT_VALUE Ben Hutchings <ben@decadent.org.uk> - 2017-04-11 21:40 +0200
    Re: [DSE-Dev] CONFIG_SECURITY_SELINUX_CHECKREQPROT_VALUE Russell Coker <russell@coker.com.au> - 2017-04-02 17:50 +0200

csiph-web