Research
.
Skip Search Box

SELinux Mailing List

Re: New strategy for enableaudit.

From: Joshua Brindle <jbrindle_at_tresys.com>
Date: Sun, 18 Dec 2005 17:35:06 -0500


Ivan Gyurdiev wrote:
>

>> This is only a short term solution until we get boolean support for 
>> dontaudit rules.  But modules could do the same thing.   This
>> gives me the ability to debug problems being covered by dontaudit 
>> rules for now though.

>
> So what's the planned solution using boolean support?
> There's a number of things that could be done here...
>
> Are you thinking of the module compiler placing dontaudit rules in a
> conditional block, based on a shared (base) boolean?
>

not automatically; the refpolicy should just have all dontaudits under a

   specific boolean. This will be easier when nested conditionals are available.

--
This message was distributed to subscribers of the selinux mailing list.
If you no longer wish to subscribe, send mail to majordomo@tycho.nsa.gov with
the words "unsubscribe selinux" without quotes as the message.
Received on Sun 18 Dec 2005 - 17:35:35 EST
 

Date Posted: Jan 15, 2009 | Last Modified: Jan 15, 2009 | Last Reviewed: Jan 15, 2009

 
bottom

National Security Agency / Central Security Service