Research
.
Skip Search Box

SELinux Mailing List

Re: Now that SELinux supports booleans should we replace tunables with booleans?

From: Stephen Smalley <sds_at_epoch.ncsc.mil>
Date: Fri, 06 Aug 2004 10:04:55 -0400


On Thu, 2004-08-05 at 09:44, Daniel J Walsh wrote:
> Here is the current patch I was using for load_policy. As has been
> stated this is not the ideal situation.
> Patching the policy.conf is probably the best solution. Utilities to
> read booleans probably usefull here.

As an interim solution, I've merged a slightly modified form of this function into libselinux and changed load_policy to call it; /sbin/init can likewise be changed to call it after the initial policy load to set the boolean values. But we'll still want to pursue a solution that lets us re-patch the boolean default settings directly in the binary policy so that there is no interval where the settings are wrong during a policy reload.

-- 
Stephen Smalley <sds@epoch.ncsc.mil>
National Security Agency


--
This message was distributed to subscribers of the selinux mailing list.
If you no longer wish to subscribe, send mail to majordomo@tycho.nsa.gov with
the words "unsubscribe selinux" without quotes as the message.
Received on Fri 6 Aug 2004 - 10:06:13 EDT
 

Date Posted: Jan 15, 2009 | Last Modified: Jan 15, 2009 | Last Reviewed: Jan 15, 2009

 
bottom

National Security Agency / Central Security Service