Research Menu

.
Skip Search Box

SELinux Mailing List

Re: Multiple contexts

From: Stephen Smalley <sds_at_epoch.ncsc.mil>
Date: Thu, 13 Jan 2005 11:44:31 -0500


On Wed, 2005-01-12 at 18:01, Luke Kenneth Casson Leighton wrote:

>  2 ) even if they did chcon -t "F1,F2" foobar, you would still expect

> them to be doing that as an "interim" measure whilst they were
> testing something _pending_ formal analysis by putting that
> into the policy files.
BTW, idle question: how do you decide whether to allow setting such combinations on a file? What happens if a file already has a
combination - how do you decide whether or not you can change those settings? Simply allowing it if you can relabel any one of the types is obviously broken...
-- 
Stephen Smalley <sds@epoch.ncsc.mil>
National Security Agency


--
This message was distributed to subscribers of the selinux mailing list.
If you no longer wish to subscribe, send mail to majordomo@tycho.nsa.gov with
the words "unsubscribe selinux" without quotes as the message.
Received on Thu 13 Jan 2005 - 11:50:51 EST
 

Date Posted: Jan 15, 2009 | Last Modified: Jan 15, 2009 | Last Reviewed: Jan 15, 2009

 
bottom

National Security Agency / Central Security Service