• [^] # Re: Sécurité dans la pile graphique

    Posté par (site web personnel) . En réponse à la dépêche Entretien avec Martin Peres, développeur Nouveau. Évalué à 3. Dernière modification le 26 octobre 2012 à 17:17.

    Ah ben ça c'est abordé dans la présentation de Martin Peres & Timothe Ravier à XDC2012 dont les slides sont ici (p 20-21) :

    Proposal: a MAC framework

    Mandatory Access Control

    • Control enforced by the system (mostly the kernel);
    • Based on a policy (no unprivileged user control).

    Suggestions

    • Should be implemented as a library to unify access control on every wayland compositors;
    • Should define which applications are allowed to take screenshots/act as virtual keyboards/copy & paste/drag & drop/register global shortcuts. . .
    • Generic model, could look like or be polkit; Integrating SELinux to use policy mecanisms.