Research
.
Skip Search Box

SELinux Mailing List

Re: patch: misc policy additions

From: Stephen Smalley <sds_at_epoch.ncsc.mil>
Date: Mon, 29 Nov 2004 09:42:09 -0500


On Sat, 2004-11-27 at 17:58, Thomas Bleher wrote:
> I do not remember the exact circumstances when I needed it. However, I
> don't think it's just relabeling between the $1_tty_device_t types. What
> if a device file loses its context? restorecon can relabel all other
> files so it just seemed logical to allow it.

IIRC, permission for relabeling those types was omitted from setfiles_t to avoid having a 'make relabel' unwittingly reset the label on your own tty (or any other active sessions). But I see your point about an explicit restorecon.

-- 
Stephen Smalley <sds@epoch.ncsc.mil>
National Security Agency


--
This message was distributed to subscribers of the selinux mailing list.
If you no longer wish to subscribe, send mail to majordomo@tycho.nsa.gov with
the words "unsubscribe selinux" without quotes as the message.
Received on Mon 29 Nov 2004 - 09:46:49 EST
 

Date Posted: Jan 15, 2009 | Last Modified: Jan 15, 2009 | Last Reviewed: Jan 15, 2009

 
bottom

National Security Agency / Central Security Service