Research
.
Skip Search Box

SELinux Mailing List

Re: Updated policy

From: Christopher J. PeBenito <cpebenito_at_tresys.com>
Date: Tue, 13 Dec 2005 14:51:30 -0500


On Sat, 2005-12-10 at 00:26 -0500, Daniel J Walsh wrote:
> Added booleans to turn on httpd connecting to mysql/postgres as well as
> relay.

merged.

> nis_signal_ypbind requires you to be able to read pidfile.

Not going to merge this, for a couple reasons. First, it would still be good to have an interface that allows just the signal, for the case that the signaler already knows the PID. Second, it introduces a large info flow backchannel, since ypbid can write it's pid file. This is a candidate for a more abstract interface whose implementation would be to call the signal interface and the read pid interface.

> mount command wants access to tty

This sounds specific to targeted since its devpts_t, shouldn't it be in a ifdef(`targeted_policy' ?

> needs to be able to search rpc_pipefs
> in Fedora.

Added an interface to handle this, rather than the raw rule.

-- 
Chris PeBenito
Tresys Technology, LLC
(410) 290-1411 x150


--
This message was distributed to subscribers of the selinux mailing list.
If you no longer wish to subscribe, send mail to majordomo@tycho.nsa.gov with
the words "unsubscribe selinux" without quotes as the message.
Received on Tue 13 Dec 2005 - 15:00:31 EST
 

Date Posted: Jan 15, 2009 | Last Modified: Jan 15, 2009 | Last Reviewed: Jan 15, 2009

 
bottom

National Security Agency / Central Security Service