Research Menu

.
Skip Search Box

SELinux Mailing List

Re: Proposed patch to policy file_contexts

From: Stephen Smalley <sds_at_epoch.ncsc.mil>
Date: Fri, 05 Mar 2004 12:18:25 -0500


On Wed, 2004-03-03 at 16:36, Karl MacMillan wrote:
> Here is an updated version that writes all of the error messages to
> stderr. There are 2 patches - the first is against the patch I sent
> before and the other is the full version.

The resulting file_contexts file maps /root entries to staff*_home_t rather than sysadm*_home_t. This is a general limitation of genhomedircon (not knowing which role to select when multiple ones are authorized), but the old one avoided the problem by skipping root and leaving the /root entries in the .fc files. Now, we could alter the ordering of roles for root in policy/users as a workaround; that shouldn't affect the default context as that is governed by /etc/security/default_contexts.

-- 
Stephen Smalley <sds@epoch.ncsc.mil>
National Security Agency


--
This message was distributed to subscribers of the selinux mailing list.
If you no longer wish to subscribe, send mail to majordomo@tycho.nsa.gov with
the words "unsubscribe selinux" without quotes as the message.
Received on Fri 5 Mar 2004 - 12:19:13 EST
 

Date Posted: Jan 15, 2009 | Last Modified: Jan 15, 2009 | Last Reviewed: Jan 15, 2009

 
bottom

National Security Agency / Central Security Service