Research
.
Skip Search Box

SELinux Mailing List

Re: [patch] refpolicy update for cap_setfcap

From: Serge E. Hallyn <serue_at_us.ibm.com>
Date: Mon, 2 Jul 2007 10:20:21 -0500


Quoting Christopher J. PeBenito (cpebenito@tresys.com):
> On Thu, 2007-06-28 at 15:17 -0400, Serge E. Hallyn wrote:
> > A tentative patch to support file capabilities introduces a new
> > CAP_SETFCAP capability. This patch adds setfcap to the refpolicy
> > access_vectors.
>
> I'd prefer to wait until the file caps code starts going upstream. It
> looks like discussions about it continue, assuming I am understanding
> the threads I've unburied from the apparmor flood.

Sure, it's in -mm, but I assume it won't be heading up to Linus' tree until a list of comments from Andrew Morgan have been suitably addressed.

thanks,
-serge

> > Index: policy/flask/access_vectors
> > ===================================================================
> > --- policy/flask/access_vectors (revision 2359)
> > +++ policy/flask/access_vectors (working copy)
> > @@ -363,6 +363,7 @@
> > lease
> > audit_write
> > audit_control
> > + setfcap
> > }
> >
> >
> >
> > --
> > This message was distributed to subscribers of the selinux mailing
> > list.
> > If you no longer wish to subscribe, send mail to
> > majordomo@tycho.nsa.gov with
> > the words "unsubscribe selinux" without quotes as the message.
> >
> >
> --
> Chris PeBenito
> Tresys Technology, LLC
> (410) 290-1411 x150

--
This message was distributed to subscribers of the selinux mailing list.
If you no longer wish to subscribe, send mail to majordomo@tycho.nsa.gov with
the words "unsubscribe selinux" without quotes as the message.
Received on Mon 2 Jul 2007 - 11:20:32 EDT
 

Date Posted: Jan 15, 2009 | Last Modified: Jan 15, 2009 | Last Reviewed: Jan 15, 2009

 
bottom

National Security Agency / Central Security Service