Cool things with SELinux... Introducing sandbox -X | Linux Today

Cool things with SELinux… Introducing sandbox -X

Written By
DW
Dan Walsh
Sep 17, 2009

“SELinux is all about defining security goals.

“For example I might have a security goal that firefox
application will not send email. So I can check if my policy
prevents firefox from sending email. But my security goal can
change depending on the content that I want to look at. For
whatever reason, I might want to allow OpenOffice to have full
access to everything in my homedir when I launch it from the start
menu, but when it is launched from firefox on untrusted content, I
only want OpenOffice to be able to display, print, or email that
content, not my credit card data….

“I introduced xguest a year or so ago, and I’ve thought about
why people liked the concept and the ways people were telling me
they were using it. (Xguest is the least privileged user, his
homedir is cleared on exit, and he is only able to connect to http
ports). I have been told that some people use xguest to go to
untrusted sites where they do not want to have bad data left
behind. Others have told me they use xguest to run games, to make
sure the downloaded games aren’t allowed to do evil things.”

Complete
Story

DW

Dan Walsh

Linux Today Logo

LinuxToday is a trusted, contributor-driven news resource supporting all types of Linux users. Our thriving international community engages with us through social media and frequent content contributions aimed at solving problems ranging from personal computing to enterprise-level IT operations. LinuxToday serves as a home for a community that struggles to find comparable information elsewhere on the web.

Property of TechnologyAdvice. © 2026 TechnologyAdvice. All Rights Reserved

Advertiser Disclosure: Some of the products that appear on this site are from companies from which TechnologyAdvice receives compensation. This compensation may impact how and where products appear on this site including, for example, the order in which they appear. TechnologyAdvice does not include all companies or all types of products available in the marketplace.