Research
.
Skip Search Box

SELinux Mailing List

Re: one line fix for tor module

From: Christopher J. PeBenito <cpebenito_at_tresys.com>
Date: Thu, 16 Mar 2006 09:14:23 -0500


On Thu, 2006-03-16 at 01:33 +0100, Erich Schubert wrote:
> Hi,
> Seems like I missed one statement for tor.

> -allow tor_t self:tcp_socket create_socket_perms;
> +allow tor_t self:tcp_socket { create_socket_perms accept };

I think what you want instead is to change it to create_stream_socket_perms, since you need to listen first before you can accept?

-- 
Chris PeBenito
Tresys Technology, LLC
(410) 290-1411 x150


--
This message was distributed to subscribers of the selinux mailing list.
If you no longer wish to subscribe, send mail to majordomo@tycho.nsa.gov with
the words "unsubscribe selinux" without quotes as the message.
Received on Thu 16 Mar 2006 - 09:14:42 EST
 

Date Posted: Jan 15, 2009 | Last Modified: Jan 15, 2009 | Last Reviewed: Jan 15, 2009

 
bottom

National Security Agency / Central Security Service