Research Menu

.
Skip Search Box

SELinux Mailing List

Re: [PATCH] SELinux - canonicalize getxattr() (fwd)

From: Stephen Smalley <sds_at_tycho.nsa.gov>
Date: Thu, 10 Nov 2005 07:31:50 -0500


On Wed, 2005-11-09 at 17:46 -0500, Daniel J Walsh wrote:
> We are supposed to be patching restorecon/chcon/setfiles to make these
> go away or at most warn. These tools should be asking the kernel for
> the correct context for a file IE shlib_t -> lib_t in targeted policy
> and then says it is ok.

I already took care of restorecon (via the modified matchpathcon logic) and setfiles (which has its own callback). But they need a kernel that has the new support for canonicalizing the contexts, and that only just showed up in 2.6.14-git13. Not in rawhide yet AFAIK.

-- 
Stephen Smalley
National Security Agency


--
This message was distributed to subscribers of the selinux mailing list.
If you no longer wish to subscribe, send mail to majordomo@tycho.nsa.gov with
the words "unsubscribe selinux" without quotes as the message.
Received on Thu 10 Nov 2005 - 07:42:19 EST
 

Date Posted: Jan 15, 2009 | Last Modified: Jan 15, 2009 | Last Reviewed: Jan 15, 2009

 
bottom

National Security Agency / Central Security Service