All of lore.kernel.org
 help / color / mirror / Atom feed
From: stefan@seekline.net (Stefan Schulze Frielinghaus)
To: refpolicy@oss.tresys.com
Subject: [refpolicy] new policy pyicqt
Date: Sun, 25 Oct 2009 22:14:36 +0100	[thread overview]
Message-ID: <1256505276.2407.48.camel@localhost> (raw)
In-Reply-To: <1256488245.16257.5.camel@localhost>

On Sun, 2009-10-25 at 17:30 +0100, Dominick Grift wrote:
> On Sun, 2009-10-25 at 16:09 +0100, Stefan Schulze Frielinghaus wrote:
> > On Sun, 2009-10-25 at 15:48 +0100, Dominick Grift wrote:
> > [...] 
> > > allow pyicqt_t self:fifo_files rw_fifo_file_perms;
> > 
> > I only included read/write perms because the app didn't complain on all
> > the other permissions which rw_fifo_file_perms will include. But if it
> > is common to use the set of permissions I will change this.
> 
> > [...] 
> > > files_spool_filetrans(pyicqt_t, pyicqt_spool_t, { dir file })
> > 
> > Why should we introduce this rule? PyICQt only writes into a directory
> > labeled as pyicqt_spool_t and therefore all new files will inherit the
> > type.
> 
> So are you saying that /var/spool/pyicq-t gets installed by the package?

PyICQt is installed by default on Fedora to run as non root user. So,
yes, /var/{run,spool}/pyicq-t is installed by the RPM package. But I
think I know what you mean. What happens if another distro runs PyICQt
as root and uses /var/run as the base pidfile directory. I will include
this rule to make sure that other distributions won't run into trouble.

[...] 
> > > files_pid_filetrans(pyicqt_t, pyicqt_var_run_t, file)
> > 
> > Same again here. Why? PyICQt writes to /var/run/pyicq-t which is labeled
> > as pyicqt_var_run_t and therefore all new files will inherit this type.
> 
> So /var/run/pyicq-t gets installed by the package?

Same as above.

[...]
> See http://oss.tresys.com/projects/refpolicy/wiki/StyleGuide

Hey, cool, wasn't aware of such a style guide. Thanks for the link and
the policy review. I will work on the suggestions and submit a new
policy.

  reply	other threads:[~2009-10-25 21:14 UTC|newest]

Thread overview: 6+ messages / expand[flat|nested]  mbox.gz  Atom feed  top
2009-10-25 11:59 [refpolicy] new policy pyicqt Stefan Schulze Frielinghaus
2009-10-25 14:48 ` Dominick Grift
2009-10-25 15:09   ` Stefan Schulze Frielinghaus
2009-10-25 16:30     ` Dominick Grift
2009-10-25 21:14       ` Stefan Schulze Frielinghaus [this message]
2009-10-26 19:40         ` Stefan Schulze Frielinghaus

Reply instructions:

You may reply publicly to this message via plain-text email
using any one of the following methods:

* Save the following mbox file, import it into your mail client,
  and reply-to-all from there: mbox

  Avoid top-posting and favor interleaved quoting:
  https://en.wikipedia.org/wiki/Posting_style#Interleaved_style

* Reply using the --to, --cc, and --in-reply-to
  switches of git-send-email(1):

  git send-email \
    --in-reply-to=1256505276.2407.48.camel@localhost \
    --to=stefan@seekline.net \
    --cc=refpolicy@oss.tresys.com \
    /path/to/YOUR_REPLY

  https://kernel.org/pub/software/scm/git/docs/git-send-email.html

* If your mail client supports setting the In-Reply-To header
  via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line before the message body.
This is an external index of several public inboxes,
see mirroring instructions on how to clone and mirror
all data and code used by this external index.