Research
.
Skip Search Box

SELinux Mailing List

Re: Added is_context_configurable function

From: Casey Schaufler <casey_at_schaufler-ca.com>
Date: Tue, 11 Jan 2005 16:19:48 -0800 (PST)

  • Colin Walters <walters@redhat.com> wrote:

> I feel that the
> on-disk version should be canonical, and the
> file_contexts only used for
> system initialization.

I'd have to recheck the LSPP spec, but the B1 requirements clearly stated that MAC labels had to be stored on the same media as the files. The "closer" the MAC attribute is to the file, the better. Hence an attribute of the file with the MAC label is prefered to a file or database. Further, the attribute must be associated with the file, not a pathname. Files can exist, after all, without a pathname.



Casey Schaufler
casey@schaufler-ca.com                          

Do you Yahoo!?
Yahoo! Mail - You care about security. So do we. http://promotions.yahoo.com/new_mail
--
This message was distributed to subscribers of the selinux mailing list.
If you no longer wish to subscribe, send mail to majordomo@tycho.nsa.gov with
the words "unsubscribe selinux" without quotes as the message.
Received on Tue 11 Jan 2005 - 19:19:51 EST
 

Date Posted: Jan 15, 2009 | Last Modified: Jan 15, 2009 | Last Reviewed: Jan 15, 2009

 
bottom

National Security Agency / Central Security Service