Research Menu

.
Skip Search Box

SELinux Mailing List

Re: Added is_context_configurable function

From: Stephen Smalley <sds_at_epoch.ncsc.mil>
Date: Wed, 12 Jan 2005 17:09:03 -0500


On Wed, 2005-01-12 at 10:48, Colin Walters wrote:
> Actually, thinking about this a bit: probably not. On my system I have
> several times changed the SELinux user identity component of file
> contexts from the default system_u to e.g. foo_u. The reason is that
> the constraints prevent a user from relabeling a file unless the SELinux
> user matches. So a list of alternate types would not be sufficient in
> this case.

<snip>
> It seems the SELinux uid, for one. Also perhaps whether or not the
> pathname is part of the standard filesystem. There seems to me to be a
> difference between a very well known file such as /etc/shadow being
> mislabeled according to file_contexts versus an unknown path such
> as /apps/web/blah.

Ok, so I take this to mean that I should await a new patchset from Dan that supports this more general way of specifying customizable contexts based on a combination of type, user identity, and file location. Yes?

-- 
Stephen Smalley <sds@epoch.ncsc.mil>
National Security Agency


--
This message was distributed to subscribers of the selinux mailing list.
If you no longer wish to subscribe, send mail to majordomo@tycho.nsa.gov with
the words "unsubscribe selinux" without quotes as the message.
Received on Wed 12 Jan 2005 - 17:15:06 EST
 

Date Posted: Jan 15, 2009 | Last Modified: Jan 15, 2009 | Last Reviewed: Jan 15, 2009

 
bottom

National Security Agency / Central Security Service