Walsh: Cool things with SELinux... Introducing sandbox -X
Walsh: Cool things with SELinux... Introducing sandbox -X
Posted Sep 22, 2009 18:22 UTC (Tue) by salimma (subscriber, #34460)In reply to: Walsh: Cool things with SELinux... Introducing sandbox -X by martinfick
Parent article: Walsh: Cool things with SELinux... Introducing sandbox -X
Managing with only user/group permission is probably impossible. Your mailbox is in the 'mail' group, say, but clearly the mail reader should be given additional permissions so that it can access the mailbox within your home directory.
At the same time, you want to prevent other users from using *their* mail readers (also in the 'mail' group, no?) from reading your mail.
