Research Menu

.
Skip Search Box

SELinux Mailing List

Re: make install fails if any users are in local.users

From: Stephen Smalley <sds_at_tycho.nsa.gov>
Date: Wed, 16 Mar 2005 10:23:53 -0500


On Wed, 2005-03-16 at 09:24 -0500, Colin Walters wrote:
> On Wed, 2005-03-16 at 08:20 -0500, Stephen Smalley wrote:
> > One question is whether setfiles -c
> > should only validate the base file_contexts configuration (which no
> > longer contains the home directory entries at all).
>
> I don't see a good alternative, really. The home directory stuff is
> entirely dynamic and outside policy build.

Ok, then the attached patches for libselinux and policycoreutils should disable processing of file_contexts.local and file_contexts.homedirs by setfiles -c.

> Perhaps though genhomedircon itself could run setfiles -c though on e.g.
> file_contexts.homedir.tmp before renaming it to file_contexts.homedir.

Yes, that is a good idea, and even with the attached patches, it should be possible to explicitly pass file_contexts.homedir.tmp to setfiles -c, so I'd encourage Dan to make that change to genhomedircon.

-- 
Stephen Smalley <sds@tycho.nsa.gov>
National Security Agency

-- This message was distributed to subscribers of the selinux mailing list. If you no longer wish to subscribe, send mail to majordomo@tycho.nsa.gov with the words "unsubscribe selinux" without quotes as the message.

Received on Wed 16 Mar 2005 - 10:37:28 EST
 

Date Posted: Jan 15, 2009 | Last Modified: Jan 15, 2009 | Last Reviewed: Jan 15, 2009

 
bottom

National Security Agency / Central Security Service