Research Menu

.
Skip Search Box

SELinux Mailing List

Re: file_contexts patch

From: Stephen Smalley <sds_at_epoch.ncsc.mil>
Date: Tue, 27 Jul 2004 09:38:03 -0400


On Mon, 2004-07-26 at 16:25, Stephen Smalley wrote:
> Would it be better to make the distro a tunable (e.g.
> policy/tunables/distro.te) and use ifdef's in the individual .te files
> and .fc files for the distro-specific changes to a given domain? I'd
> particularly like to see all of the RedHat-specific changes moved from
> rpm.{te,fc} into something that is clearly specific to RedHat.

Note that in addition to reviewing the contents of rpm.te and rpm.fc for RedHat-specific customizations, this change would require reviewing all uses of ifdef(`rpm.te') throughout the various .te files, as some of those conditional blocks are for RedHat-specific customizations while others are for rules that should always be included when the rpm domain is enabled in the policy (and thus should still be included for other rpm-using distros).

-- 
Stephen Smalley <sds@epoch.ncsc.mil>
National Security Agency


--
This message was distributed to subscribers of the selinux mailing list.
If you no longer wish to subscribe, send mail to majordomo@tycho.nsa.gov with
the words "unsubscribe selinux" without quotes as the message.
Received on Tue 27 Jul 2004 - 09:38:55 EDT
 

Date Posted: Jan 15, 2009 | Last Modified: Jan 15, 2009 | Last Reviewed: Jan 15, 2009

 
bottom

National Security Agency / Central Security Service