All of lore.kernel.org
 help / color / mirror / Atom feed
From: guido@trentalancia.com (Guido Trentalancia)
To: refpolicy@oss.tresys.com
Subject: [refpolicy] [PATCH 13/34]: patch to allow networkmanager dbus chat
Date: Wed, 09 Mar 2011 10:49:11 +0100	[thread overview]
Message-ID: <1299664151.1680.11.camel@tesla.lan> (raw)
In-Reply-To: <1e2c5493-fd5d-4770-8bfe-fb0b0ad05234@email.android.com>

Hi Russell,

thanks for your reply.

On Wed, 09/03/2011 at 19.03 +1100, Russell Coker wrote:
> 
>  think my latest reply was not the proper answer to your question.
> >What
> >I meant for "everything is running as xdm_t" is that as a normal user
> >if
> >you type "id -Z" from the gnome-terminal, then you get xdm_t (which
> >still looks suspicious to me).
> 
> That usually means that you don't have PAM configured correctly.  Probably your xdm is not compiled with SE support and you are not using pam_selinux.so .

The first. It's a simple pam config without pam_selinux.so (for gdm). I
think I had removed it temporarily because it was causing issues.

> >It's just something very simple. A make target which runs ps axZ (as
> >sysadm) and compares a few very basic things:
> >
> >- if init has properly transitioned to its context (apparently at the
> >moment no one cares if it hasn't, which is quite worrying as everything
> 
> I am working on test VMs for Debian now and plan to do such things.

Excellent. What do you mean for VMs ? In any case if you have time to do
it then please try to do something which applies to everybody and can
then be customized for Debian if necessary.

Christopher did not comment on this (yet)...

> >By the way, Tresys' SMTP server is blocking some mail from dynamically
> >allocated mobile Internet connections (using barracudanetworks.com). I
> 
> You shoud configure your phone to send through a smart host.  I am going to run such a server for SE testing, contact me off list for an account.

Yes, of course if I change my SMTP server... But most people are not
bothered of doing that. I think the idea behind stuff such as barracuda
is good but unfortunately it does not be apply very well to the case of
dynamically assigned addresses.

I had to reply on the list in any case because of the other issues.
Perhaps you can send me an account off-list... The same thing happened
with your address Russell.

Regards,

Guido

  reply	other threads:[~2011-03-09  9:49 UTC|newest]

Thread overview: 21+ messages / expand[flat|nested]  mbox.gz  Atom feed  top
2011-02-16  6:13 [refpolicy] [PATCH 13/34]: patch to allow networkmanager dbus chat Guido Trentalancia
2011-02-23 14:36 ` Christopher J. PeBenito
2011-02-23 18:50   ` Guido Trentalancia
2011-03-07 13:56     ` Christopher J. PeBenito
2011-03-07 17:09       ` Guido Trentalancia
2011-03-07 19:37         ` Christopher J. PeBenito
2011-03-07 21:39           ` Guido Trentalancia
2011-03-09  8:03             ` Russell Coker
2011-03-09  9:49               ` Guido Trentalancia [this message]
2011-03-09 11:23                 ` Russell Coker
2011-03-09 14:41                   ` Guido Trentalancia
2011-03-09 14:59                     ` Russell Coker
2011-03-09 15:34                       ` [refpolicy] run/build-time sanity checks Guido Trentalancia
2011-03-10  1:14                         ` Russell Coker
2011-03-14 12:42             ` [refpolicy] [PATCH 13/34]: patch to allow networkmanager dbus chat Christopher J. PeBenito
2011-03-14 17:23               ` Guido Trentalancia
2011-03-14 18:04                 ` Christopher J. PeBenito
2011-03-15 13:40                   ` Guido Trentalancia
2011-03-10 21:53           ` Guido Trentalancia
2011-03-14 12:44             ` Christopher J. PeBenito
2011-03-14 17:26               ` Guido Trentalancia

Reply instructions:

You may reply publicly to this message via plain-text email
using any one of the following methods:

* Save the following mbox file, import it into your mail client,
  and reply-to-all from there: mbox

  Avoid top-posting and favor interleaved quoting:
  https://en.wikipedia.org/wiki/Posting_style#Interleaved_style

* Reply using the --to, --cc, and --in-reply-to
  switches of git-send-email(1):

  git send-email \
    --in-reply-to=1299664151.1680.11.camel@tesla.lan \
    --to=guido@trentalancia.com \
    --cc=refpolicy@oss.tresys.com \
    /path/to/YOUR_REPLY

  https://kernel.org/pub/software/scm/git/docs/git-send-email.html

* If your mail client supports setting the In-Reply-To header
  via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line before the message body.
This is an external index of several public inboxes,
see mirroring instructions on how to clone and mirror
all data and code used by this external index.