Research Menu

.
Skip Search Box

SELinux Mailing List

Re: idea: setfiles to exclude specific type

From: Colin Walters <walters_at_verbum.org>
Date: Mon, 22 Nov 2004 14:20:01 -0500


On Mon, 2004-11-22 at 10:54 -0500, Yuichi Nakamura wrote:
> Hello.
>
> I add setfiles "-x" option.
> I attach my idea in "setfiles.diff".
>
> -x option is used to exclude specified type.
>
> For example,
> # setfiles file_contexts /home -x httpd_user_rw_t
> setfiles skips relabeling files that have "httpd_user_rw_t".

I thought the conclusion from previous discussion on user-customizable file contexts was that we were going to add notation to file_contexts for groups of contexts, so that all of e.g.

system_u:object_r:httpd_sys_content_t,
system_u:object_r:httpd_sys_script_exec_t, 
system_u:object_r:httpd_sys_script_rw_t,
etc. would be acceptable.

For example:

/var/www(/.*)? system_u:object_r:httpd_sys_content_t system_u:object_r:httpd_sys_script_rw_t system_u:object_r:httpd_sys_script_exec_t ...

--
This message was distributed to subscribers of the selinux mailing list.
If you no longer wish to subscribe, send mail to majordomo@tycho.nsa.gov with
the words "unsubscribe selinux" without quotes as the message.

Received on Mon 22 Nov 2004 - 14:20:17 EST
 

Date Posted: Jan 15, 2009 | Last Modified: Jan 15, 2009 | Last Reviewed: Jan 15, 2009

 
bottom

National Security Agency / Central Security Service