Research
.
Skip Search Box

SELinux Mailing List

Re: new file contexts

From: Stephen Smalley <sds_at_tislabs.com>
Date: Fri, 23 Aug 2002 09:50:03 -0400 (EDT)

On 23 Aug 2002, Timothy Wood wrote:

> When you make a new file in the policy/file_contexts/program directory
> do you have to specify the new file somewhere so that it gets compiled
> into the policy or should it just pickup the new file automatically?

The policy/Makefile automatically includes up a program .fc file into the file contexts configuration for each program .te file that exists under domains/program. This approach is designed to permit users to remove program .te files for programs that they do not run and have the corresponding .fc files automatically ignored. However, you may encounter problems in selectively removing program .te files, since there may be other .te files that have dependencies on them. We are trying to wrap all such inter-domain dependencies with m4 ifdefs, but that is not yet complete.

--
Stephen D. Smalley, NAI Labs
ssmalley@nai.com




--
This message was distributed to subscribers of the selinux mailing list.
If you no longer wish to subscribe, send mail to majordomo@tycho.nsa.gov with
the words "unsubscribe selinux" without quotes as the message.
Received on Fri 23 Aug 2002 - 10:17:00 EDT
 

Date Posted: Jan 15, 2009 | Last Modified: Jan 15, 2009 | Last Reviewed: Jan 15, 2009

 
bottom

National Security Agency / Central Security Service