Research Menu

.
Skip Search Box

SELinux Mailing List

Re: Announce: SELinux conditional policy extensions

From: Joshua D. Guttman <guttman_at_mitre.org>
Date: 16 Feb 2004 16:20:32 -0500


When you refer to conflicting rules, what do you mean?

Thanks --

        Joshua

>From README-COND:

> - Policy conflicts with policy
>
> Non-conditional policy rules take preference over conditional
> rules. In most cases, a conflicting conditional rule is
> discarded. In some cases, the policy compiler will exit with an
> error. The list below describes the conflicts and the results:
>
> - A conditional type rule conflicts with a non-conditional type
> rule
>
> The conditional type rule is discarded and the compiler issues
> a warning.
>
> - A conditional type rule in one conditional policy block
> conflicts with a conditional type rule in a different
> conditional policy block.
>
> The previously processed rule is kept, the second is discarded.
>

-- 
	Joshua D. Guttman		<guttman@mitre.org>
	MITRE, Mail Stop S119		Office:	+1 781 271 2654
	202 Burlington Rd.		Fax:	+1 781 271 8953
	Bedford, MA 01730-1420 USA	Cell:	+1 781 526 5713



--
This message was distributed to subscribers of the selinux mailing list.
If you no longer wish to subscribe, send mail to majordomo@tycho.nsa.gov with
the words "unsubscribe selinux" without quotes as the message.
Received on Mon 16 Feb 2004 - 16:28:32 EST
 

Date Posted: Jan 15, 2009 | Last Modified: Jan 15, 2009 | Last Reviewed: Jan 15, 2009

 
bottom

National Security Agency / Central Security Service