Research
.
Skip Search Box

SELinux Mailing List

Re: Added is_context_configurable function

From: Daniel J Walsh <dwalsh_at_redhat.com>
Date: Thu, 13 Jan 2005 09:57:46 -0500


Stephen Smalley wrote:

>On Wed, 2005-01-12 at 10:48, Colin Walters wrote:
>
>
>>Actually, thinking about this a bit: probably not. On my system I have
>>several times changed the SELinux user identity component of file
>>contexts from the default system_u to e.g. foo_u. The reason is that
>>the constraints prevent a user from relabeling a file unless the SELinux
>>user matches. So a list of alternate types would not be sufficient in
>>this case.
>>
>>
><snip>
>
>
>>It seems the SELinux uid, for one. Also perhaps whether or not the
>>pathname is part of the standard filesystem. There seems to me to be a
>>difference between a very well known file such as /etc/shadow being
>>mislabeled according to file_contexts versus an unknown path such
>>as /apps/web/blah.
>>
>>
>
>Ok, so I take this to mean that I should await a new patchset from Dan
>that supports this more general way of specifying customizable contexts
>based on a combination of type, user identity, and file location. Yes?
>
>
>

No. I gave a patch to handle user customizable file_context (file_context.local) which will sort of do this. Restorecon/setfiles currently modify the user section of the file_context which should stop unless you specify a -F this would preserve the functionality that Colin wants.

Dan

--
This message was distributed to subscribers of the selinux mailing list.
If you no longer wish to subscribe, send mail to majordomo@tycho.nsa.gov with
the words "unsubscribe selinux" without quotes as the message.
Received on Thu 13 Jan 2005 - 09:58:04 EST
 

Date Posted: Jan 15, 2009 | Last Modified: Jan 15, 2009 | Last Reviewed: Jan 15, 2009

 
bottom

National Security Agency / Central Security Service