Research
.
Skip Search Box

SELinux Mailing List

Re: RH8 policy support

From: Russell Coker <russell_at_coker.com.au>
Date: Sat, 5 Oct 2002 08:28:09 +0200


On Fri, 4 Oct 2002 23:14, Brad Chapman wrote:
> > Wrappers for rpm and related commands to run them in system_u:system_r .
>
> I can certainly try this, but it will be ugly and evil and will need some
> major cleanups before going into the CVS.

No, just copy my code for wrapping dpkg.

> > Support for relabelling files after installing a new RPM package.
>
> How would you do that?

rpm triggers should do it, just need to call a script that gets a list of files in the package and then uses "setfiles -s" to relabel them.

> > Policy to make the install scripts start daemons in the correct domain.
>
> What install scripts do you mean?

Well if you install a new version of cron then the package manager has to stop the old version and start the new version. You don't want cron running in the rpm_t domain...

-- 
http://www.coker.com.au/selinux/   My NSA Security Enhanced Linux packages
http://www.coker.com.au/bonnie++/  Bonnie++ hard drive benchmark
http://www.coker.com.au/postal/    Postal SMTP/POP benchmark
http://www.coker.com.au/~russell/  My home page


--
This message was distributed to subscribers of the selinux mailing list.
If you no longer wish to subscribe, send mail to majordomo@tycho.nsa.gov with
the words "unsubscribe selinux" without quotes as the message.
Received on Sat 5 Oct 2002 - 02:37:58 EDT
 

Date Posted: Jan 15, 2009 | Last Modified: Jan 15, 2009 | Last Reviewed: Jan 15, 2009

 
bottom

National Security Agency / Central Security Service