Re: file labeling (was Re: applications and ports)

From: Stephen Smalley <sds_at_tislabs.com>
Date: Tue, 29 Jan 2002 11:48:53 -0500 (EST)

On Tue, 29 Jan 2002, Paul Krumviede wrote:

> i would emphasize this last sentence, as i've confused myself by
> failing to track manually labeled files in file_contexts only to have
> policy changes fail to work unexpectedly after i'd relabel the
> file system.

It might be nice to have a tool that traverses the filesystem, compares the file labels with the existing file_contexts configuration, and generates an updated file_contexts based on the current state. This could be implemented as an option to the existing setfiles program.

At present, you could generate a complete mapping of the current state using the modified ls or find programs, but that would lack the conciseness and generality of the file_contexts configuration.

> as an aside, the default install for file-utils in the latest release
> doesn't seem to install the chcon man page, so i didn't find
> the option to not dereference symbolic links for a bit.

Sorry. As a side note, the --help option often works. Also, there are the simple chsid and lchsid test programs.

--
Stephen D. Smalley, NAI Labs
ssmalley@nai.com




--
You have received this message because you are subscribed to the selinux list.
If you no longer wish to subscribe, send mail to majordomo@tycho.nsa.gov with
the words "unsubscribe selinux" without quotes as the message.
Received on Tue 29 Jan 2002 - 12:00:48 EST

This archive was generated by hypermail 2.2.0 on Wed 11 Jun 2008 - 08:10:26 EDT