Research
.
Skip Search Box

SELinux Mailing List

Re: MLS and default file contexts

From: Stephen Smalley <sds_at_tycho.nsa.gov>
Date: Tue, 18 Dec 2007 11:36:05 -0500


On Tue, 2007-12-18 at 10:16 -0600, Ted X Toth wrote:
> As best I can tell the current implementation requires a context to have
> a level or range to be valid in an fc file. However there a cases where
> I'd prefer that files be created with a given context but at the level
> of the creating process. Is there a way to do specify this behavior in
> an fc file?

The fc files are just to provide install-time defaults for file labels. Runtime creation of files is governed by policy; in the case of MLS, this is inherit-from-creator unless a range transition rule is specified.

So the only real issue is exempting runtime files from a relabel, which can be done by specifying a <<none>> entry in a fc file, or putting a "customizable file context" on the file, or excluding that tree from relabels.

-- 
Stephen Smalley
National Security Agency


--
This message was distributed to subscribers of the selinux mailing list.
If you no longer wish to subscribe, send mail to majordomo@tycho.nsa.gov with
the words "unsubscribe selinux" without quotes as the message.
Received on Tue 18 Dec 2007 - 11:36:09 EST
 

Date Posted: Jan 15, 2009 | Last Modified: Jan 15, 2009 | Last Reviewed: Jan 15, 2009

 
bottom

National Security Agency / Central Security Service