Research
.
Skip Search Box

SELinux Mailing List

Re: We need a tool to extract the file context contents out of a policy package.

From: Daniel J Walsh <dwalsh_at_redhat.com>
Date: Sat, 11 Mar 2006 09:39:41 -0500


Ivan Gyurdiev wrote:
> Daniel J Walsh wrote:
>> If we had this we could do something like
>>
>> fixfiles -P mypolicy.pp
>>
>> And it would restorecon over the file context.
> - what if the contexts used are defined in another module that isn't
> linked yet?

Then it will not work, but I don't see that as a real problem.
> - what if the contexts are in this module, but it isn't loaded?
Ditto
>
> - what about genhomedircon processing?
>

Perhaps, but usually not necessary. We could have fixfiles run genhomedircon before restoring context.
> Why can't we do this in semanage_commit()?
I think the indeterminate time could be a problem. semodule -i could take a half hour...

--
This message was distributed to subscribers of the selinux mailing list.
If you no longer wish to subscribe, send mail to majordomo@tycho.nsa.gov with
the words "unsubscribe selinux" without quotes as the message.
Received on Sat 11 Mar 2006 - 09:39:57 EST
 

Date Posted: Jan 15, 2009 | Last Modified: Jan 15, 2009 | Last Reviewed: Jan 15, 2009

 
bottom

National Security Agency / Central Security Service