Security Enhanced Linux
What's New
Frequently Asked Questions
Background
Documents
License
Download
Participating
Mail List
Archives
Remaining Work
Contributors
Related Work
Press Releases
Information Assurance Research
NIARL In-house Research Areas
Mathematical Sciences Program
Sabbaticals
Computer & Information Sciences Research
Technology Transfer
Advanced Computing
Advanced Mathematics
Communications & Networking
Information Processing
Microelectronics
Other Technologies
Technology Fact Sheets
Publications
Related Links
|
SELinux Mailing ListRe: Updated policy
From: Stephen Smalley <sds_at_epoch.ncsc.mil>
Date: Thu, 27 Jan 2005 11:22:04 -0500
I merged these bits into sourceforge CVS.
> allow mount_t binfmt_misc_fs_t:dir mounton; Waiting on clarification of whether and why this is needed, given that the mount point should be sysctl_t and only the mounted directory should have this type. Multiple mounts?
> Changes to allow setfiles/restorecon to read default_context_t I merged these bits into sourceforge CVS.
> Fixes for postgresql.te Ditto.
> Elimination of gpg execmod change. The gpg rpm was fixed in rawhide. Ditto.
> Fixes for targeted crond to run as unconfined and still have transitions Waiting on clarification of whether we truly want separate domains at all for such programs in the targeted policy, and whether it should be in system_crond_t or crond_t. Also merged most of the miscellaneous bits of the patch, excepting execmem permission for mozilla and the usual tunables and distros customizations. -- Stephen Smalley <sds@epoch.ncsc.mil> National Security Agency -- This message was distributed to subscribers of the selinux mailing list. If you no longer wish to subscribe, send mail to majordomo@tycho.nsa.gov with the words "unsubscribe selinux" without quotes as the message.Received on Thu 27 Jan 2005 - 11:28:30 EST |
|
Date Posted: Jan 15, 2009 | Last Modified: Jan 15, 2009 | Last Reviewed: Jan 15, 2009 |