All of lore.kernel.org
 help / color / mirror / Atom feed
From: "Christopher J. PeBenito" <cpebenito@tresys.com>
To: Erich Schubert <erich@debian.org>
Cc: SE Linux <selinux@tycho.nsa.gov>
Subject: Re: refpolicy updates from debian
Date: Tue, 05 Sep 2006 10:02:20 -0400	[thread overview]
Message-ID: <1157464940.3199.250.camel@sgc> (raw)
In-Reply-To: <1157399016.4446.20.camel@wintermute.xmldesign.de>

On Mon, 2006-09-04 at 21:43 +0200, Erich Schubert wrote:
> > - dropped netuser
> 
> I'm still convinced it's useful.
> It's an easy way of allowing only certain users to setup network
> servers.
> If like, 10% of your users should be allowed to setup network servers,
> the others should not.

I see where it would be useful, I just don't believe its common enough
to be added.

> > - please make a more descriptive name for usbmodules_var_lib_t.  maybe
> > usbmodules_ids_t?
> 
> Right now there is only the usbmodules ids file in there, so that name
> is fine with me. I have no idea if usbmodules might get extra var files
> later on. AFAICT the file is generated from one single source file on my
> system anyway. That might differ for certain USB hardware not supported
> by the stock kernel, though.

After doing a little digging to see where these files are on FC and
Gentoo machines, I see that the existing hwdata_t is the right type for
this.  I have added the appropriate rules and fc entries.  However, I
don't see any options for usbmodules that would have it write to
usb.ids, so why does your patch have this access?

> > - why does system_crond_t connect to mysql?
> 
> I'm not sure, I believe it's cron signaling mysql some maintainance.
> I don't actually use MySQL.
> 
> >From the cronjob:
> # This script only rotates the binary logs. The normal logs are rotated
> # via /etc/logrotate.d/mysql-server.
> 
> I don't know why logrotate is not used for the binary logs, too.

Can you send me a copy of the script off list?

-- 
Chris PeBenito
Tresys Technology, LLC
(410) 290-1411 x150


--
This message was distributed to subscribers of the selinux mailing list.
If you no longer wish to subscribe, send mail to majordomo@tycho.nsa.gov with
the words "unsubscribe selinux" without quotes as the message.

  reply	other threads:[~2006-09-05 14:00 UTC|newest]

Thread overview: 7+ messages / expand[flat|nested]  mbox.gz  Atom feed  top
2006-09-02  1:37 refpolicy updates from debian Erich Schubert
2006-09-04 18:21 ` Christopher J. PeBenito
2006-09-04 19:43   ` Erich Schubert
2006-09-05 14:02     ` Christopher J. PeBenito [this message]
2006-09-05 14:33       ` Erich Schubert
2006-09-05 14:37         ` Christopher J. PeBenito
2006-09-05 16:19           ` Erich Schubert

Reply instructions:

You may reply publicly to this message via plain-text email
using any one of the following methods:

* Save the following mbox file, import it into your mail client,
  and reply-to-all from there: mbox

  Avoid top-posting and favor interleaved quoting:
  https://en.wikipedia.org/wiki/Posting_style#Interleaved_style

* Reply using the --to, --cc, and --in-reply-to
  switches of git-send-email(1):

  git send-email \
    --in-reply-to=1157464940.3199.250.camel@sgc \
    --to=cpebenito@tresys.com \
    --cc=erich@debian.org \
    --cc=selinux@tycho.nsa.gov \
    /path/to/YOUR_REPLY

  https://kernel.org/pub/software/scm/git/docs/git-send-email.html

* If your mail client supports setting the In-Reply-To header
  via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line before the message body.
This is an external index of several public inboxes,
see mirroring instructions on how to clone and mirror
all data and code used by this external index.