Now that Fedora 8 is approaching completion, I have cut a new version of xguest.rpm
You must be fully updated to the latest rawhide.
To install you can copy down the rpm then execute
yum install --nogpgcheck xguest-1.0.1-2.fc8.noarch.rpm
This should also bring in the latest sabayon code.
This rpm will create an xguest user account with a disabled password.
You can not log into this account by anything but gdm when SELinux is in enforcing mode.
It uses pam_selinux_permit to perform this magic.
This rpm sets up pam_namespace to mount a temporary file system for /tmp, /var/tmp and $HOME.
It also uses sabayon to change the default login. Basically it removes any of the privledged panel apps that a normal login session would run
setroubleshoot, network manager, performance manager. logout.
You should have a full login session, but not be able to talk to any network ports, other then using firefox to talk to the web, other apps like curl , and links will fail. You can not run any setuid applications.
Try it out and tell me what you think.
(Anonymous)
2007-10-24 03:29 am (UTC)
We are thinking about this.
2007-10-25 04:17 pm (UTC)
I guess if it has enough use.
NetworkManager
2007-10-28 03:08 am (UTC)
Re: NetworkManager
(Anonymous)
2007-10-29 04:37 pm (UTC)
If for some reason it really can't set up a network connection without communicating with processes owned by the user logged in to the console, there are alternative ways to handle network management.
Re: NetworkManager
2007-11-02 06:28 pm (UTC)
require {
type xguest_t;
}
#============= xguest_t ==============
networkmanager_dbus_chat(xguest_t)
This will allow the xguest user to run nm-applet to communicate with the NetworkManager. You would need to use sabayon to read nm-applet as a application on startup also.
2008-07-11 01:38 am (UTC)
2008-07-10 10:52 pm (UTC)
cd change
(Anonymous)
2007-11-10 08:51 pm (UTC)
wonderful music recommended to all. What listen you ? please write here :)
buy buy
Persistent Changes?
2007-11-12 07:56 pm (UTC)
Adjusting the xguest homedir
2007-11-12 08:41 pm (UTC)
http://www.gnome.org/projects/sabay
Every time you login the gnome scrips execute sabayon-apply which reads
/etc/desktop-profiles/users.xml
for a mapping between the login user name and the sabayon zip file
cat /etc/desktop-profiles/users.xml
You will see the xguest.zip file there. If you want to modify the xguest login, you need to install sabayon (gui) tool, and run it. You can then select the xguest.zip file and change the gnome session on login.
Re: Adjusting the xguest homedir
(Anonymous)
2007-12-14 03:51 pm (UTC)
When i edit xguest some selinux errors appear then it fails on saving...
Any alternatives?
===== BEGIN MILESTONES (/usr/sbin/sabayon) =====
MainThread 2007/12/14 17:38:13.0121 (admin-tool): Creating profiles dialog
MainThread 2007/12/14 17:38:13.2246 (admin-tool): Starting main loop
MainThread 2007/12/14 17:39:28.4953 (admin-tool): Got fatal error: sabayon-session exited with a FATAL ERROR (exit code 1)
MainThread 2007/12/14 17:39:40.6043 (admin-tool): Terminating main loop
MainThread 2007/12/14 17:39:40.6044 (admin-tool): Exiting abnormally; dumping log due to a fatal error
===== END MILESTONES (/usr/sbin/sabayon) =====
===== BEGIN RING BUFFER (/usr/sbin/sabayon) =====
MainThread 2007/12/14 17:38:13.0121 (admin-tool): Creating profiles dialog
MainThread 2007/12/14 17:38:13.2246 (admin-tool): Starting main loop
MainThread 2007/12/14 17:38:15.6926 (USER): Starting to edit profile 'xguest'
MainThread 2007/12/14 17:39:28.4953 (admin-tool): Got fatal error: sabayon-session exited with a FATAL ERROR (exit code 1)
MainThread 2007/12/14 17:39:40.6038 (USER): Finishing editing profile
MainThread 2007/12/14 17:39:40.6043 (admin-tool): Terminating main loop
MainThread 2007/12/14 17:39:40.6044 (admin-tool): Exiting abnormally; dumping log due to a fatal error
===== END RING BUFFER (/usr/sbin/sabayon) =====
This configuration for the debug log can be re-created
by putting the following in /root/sabayon-debug-log.conf
(use ';' to separate domain names):
[debug log]
2008-07-11 06:56 am (UTC)
another requem
(Anonymous)
2007-11-15 03:31 am (UTC)
buy buy http://18years.hot-adult-portals.info/
first coming
(Anonymous)
2007-12-25 12:43 pm (UTC)
nWIwxeazZIOuHD
(Anonymous)
2008-03-27 11:00 am (UTC)
EMmRANecOByMXRupSA
(Anonymous)
2008-03-27 03:10 pm (UTC)
works for me
2008-04-14 12:53 am (UTC)
John.
Re: works for me
2008-06-16 04:19 pm (UTC)
Regards
Bob
Rent-a-Website