Research Menu

.
Skip Search Box

SELinux Mailing List

Re: [RFC] Upstream policy handling

From: Christopher J. PeBenito <cpebenito_at_tresys.com>
Date: Mon, 20 Sep 2004 08:56:10 -0400


On Sun, 2004-09-19 at 23:33, Colin Walters wrote:
> As we discussed on IRC, at least for the sysadmfile removals, there's an
> easy way to preserve the existing semantics and keep the patch
> mergeable: just use another attribute instead of sysadmfile.

And my response was that it was not a clean way to do it imo. I think sysadmfile is an overused attribute. You're suggesting adding another attribute to fix an attribute problem. The way I did it was to reduce the sysadmfile types, and then add a tunable that gives back full access if needed by using { file_type -shadow_t }, which is basically what sysadmfile is currently. If there are other references to sysadmfile, they can also be replaced with the above set. I don't see how this is less mergeable.

-- 
Chris PeBenito
Tresys Technology, LLC
(410) 290-1411 x150



--
This message was distributed to subscribers of the selinux mailing list.
If you no longer wish to subscribe, send mail to majordomo@tycho.nsa.gov with
the words "unsubscribe selinux" without quotes as the message.
Received on Mon 20 Sep 2004 - 08:55:01 EDT
 

Date Posted: Jan 15, 2009 | Last Modified: Jan 15, 2009 | Last Reviewed: Jan 15, 2009

 
bottom

National Security Agency / Central Security Service