Security Enhanced Linux
What's New
Frequently Asked Questions
Background
Documents
License
Download
Participating
Mail List
Archives
Remaining Work
Contributors
Related Work
Press Releases
Information Assurance Research
NIARL In-house Research Areas
Mathematical Sciences Program
Sabbaticals
Computer & Information Sciences Research
Technology Transfer
Advanced Computing
Advanced Mathematics
Communications & Networking
Information Processing
Microelectronics
Other Technologies
Technology Fact Sheets
Publications
Related Links
|
SELinux Mailing ListRe: libsemage patch to not compile modules for seusers and fcontext
From: Joshua Brindle <jbrindle_at_tresys.com>
Date: Fri, 12 Sep 2008 14:53:28 -0400
>>>> I'm a little unclear on what this is doing - can you clarify? >>>> >>> This is clearing the existing seusers.final file, otherwise delete was >>> not working. >>> >> I think the previous code was doing more - it was merging the local file >> with the shipped base package file, like this: >> >> data = extract_file_from_policy_package( ) >> write_file ( "seusers.final", data ) >> if ( data != null ) { >> seusers.clear_cache() // thereby forcing reload from >> seusers.final when cache() is called again (in merge_components) >> } else { >> seusers.clear() >> } >> >> It's also doing this three times (once for fcontexts, once for seusers, >> once for seusers_extra). >> The problem is that you're skipping the link_sandbox call, which builds >> the base package, containing this information. >> >> Ivan >> >> > Ok I found some problems with the previous patch and did some code > reuse. I added a function that only read base.pp in order to handle the > base user_extra and seusers problem. > > > -----BEGIN PGP SIGNATURE----- > Version: GnuPG v1.4.9 (GNU/Linux) > Comment: Using GnuPG with Fedora - http://enigmail.mozdev.org > > iEYEARECAAYFAkjH2e8ACgkQrlYvE4MpobM/KwCZAQQ/GCqo2qtHVrwKdvSVyVsW > yr4An16jcLDYVX6tjzwRXRJ1kL4tugcf > =8o75 > -----END PGP SIGNATURE----- > The patch looks good but the test looks like it was written to be standalone and make test under libsemanage won't compile anymore (duplicate definition of main()). Please use the CUnit test infrastructure we have in place. -- This message was distributed to subscribers of the selinux mailing list. If you no longer wish to subscribe, send mail to majordomo@tycho.nsa.gov with the words "unsubscribe selinux" without quotes as the message.Received on Fri 12 Sep 2008 - 14:53:41 EDT |
|
Date Posted: Jan 15, 2009 | Last Modified: Jan 15, 2009 | Last Reviewed: Jan 15, 2009 |