Research
.
Skip Search Box

SELinux Mailing List

Re: [RFC & PATCH] inherited type definition.

From: Luke Kenneth Casson Leighton <lkcl_at_lkcl.net>
Date: Thu, 24 Mar 2005 22:19:54 +0000


On Thu, Mar 24, 2005 at 09:31:41PM +0900, Kaigai Kohei wrote:
> Hello,
>
> > and your original question was: when you use A "extends" B and C
> > "extends" B, and B contains "@"s, how do you potentially make A
> > ignore the "@" but C _not_ ignore the "@"?
>
> That means as follows, doesn't it ?
> <type B>
> + <type A>
> + <type C>
 

 yes.

> "allow foo_t @B - @C:file getattr ;" is rolled out to
> "allow foo_t {B A}:file getattr ;" as you want.

 ah ha!

 great.

 l.

--
This message was distributed to subscribers of the selinux mailing list.
If you no longer wish to subscribe, send mail to majordomo@tycho.nsa.gov with
the words "unsubscribe selinux" without quotes as the message.
Received on Thu 24 Mar 2005 - 17:10:28 EST
 

Date Posted: Jan 15, 2009 | Last Modified: Jan 15, 2009 | Last Reviewed: Jan 15, 2009

 
bottom

National Security Agency / Central Security Service