All of lore.kernel.org
 help / color / mirror / Atom feed
From: Luke Kenneth Casson Leighton <lkcl@lkcl.net>
To: Russell Coker <russell@coker.com.au>
Cc: Thomas Hood <jdthood@aglu.demon.nl>,
	258725@bugs.debian.org,
	"Alexander E. Patrakov" <patrakov@ums.usu.ru>,
	SE-Linux <selinux@tycho.nsa.gov>
Subject: Re: Bug#258725: Location of net.agent
Date: Mon, 12 Jul 2004 20:44:52 +0100	[thread overview]
Message-ID: <20040712194451.GA7550@lkcl.net> (raw)
In-Reply-To: <200407122116.36896.russell@coker.com.au>

i been thinking a bit more.

perhaps there should be a debian installer-option which specifies the
directory for state information: it should be a high-priority option
and should end up placing the writeable-directory-location into
/etc/default/hotplug under some appropriate variable, e.g.
STATE_DIRECTORY.

then, wherever hotplug refers to /etc/hotplug to write files, place
$(STATE_DIRECTORY) in front of it, which is read from
/etc/default/hotplug.

the information presented to the person doing the installation should
be something like this:

	"Please type in [select?] a directory location for hotplug to
	 put its state information.

	Bear in mind that the directory must be writeable very early in
	start-up time, so if you select /var/run/hotplug, for example,
	and /var is NFS mounted, the directory may not yet be accessible.

	If you are running a really weird non-standard system (NFS mounted,
	lots of partitions, an SE/Linux system with read-only access to /etc,
	you may wish to use /devfs/shm/tmp.

	If you do not know what this is all talking about, just press
	<return> to select /etc/hotplug/run as the default"

this will at least allow people to install systems that will work in
almost all cases.

l.

On Mon, 12 Jul 2004 18:33, Luke Kenneth Casson Leighton <lkcl@lkcl.net> wrote:
>  by recommending a subdirectory, it is possible to do the
>  selinux-equivalent of setgid, such that any file in that
>  subdirectory will be made writeable to the hotplug scripts.

--
This message was distributed to subscribers of the selinux mailing list.
If you no longer wish to subscribe, send mail to majordomo@tycho.nsa.gov with
the words "unsubscribe selinux" without quotes as the message.

      reply	other threads:[~2004-07-12 19:34 UTC|newest]

Thread overview: 3+ messages / expand[flat|nested]  mbox.gz  Atom feed  top
     [not found] <20040711145538.GA15954@wonderland.linux.it>
     [not found] ` <1089615747.2520.213.camel@localhost.localdomain>
2004-07-12  8:33   ` Bug#258725: Location of net.agent Luke Kenneth Casson Leighton
2004-07-12 11:16     ` Russell Coker
2004-07-12 19:44       ` Luke Kenneth Casson Leighton [this message]

Reply instructions:

You may reply publicly to this message via plain-text email
using any one of the following methods:

* Save the following mbox file, import it into your mail client,
  and reply-to-all from there: mbox

  Avoid top-posting and favor interleaved quoting:
  https://en.wikipedia.org/wiki/Posting_style#Interleaved_style

* Reply using the --to, --cc, and --in-reply-to
  switches of git-send-email(1):

  git send-email \
    --in-reply-to=20040712194451.GA7550@lkcl.net \
    --to=lkcl@lkcl.net \
    --cc=258725@bugs.debian.org \
    --cc=jdthood@aglu.demon.nl \
    --cc=patrakov@ums.usu.ru \
    --cc=russell@coker.com.au \
    --cc=selinux@tycho.nsa.gov \
    /path/to/YOUR_REPLY

  https://kernel.org/pub/software/scm/git/docs/git-send-email.html

* If your mail client supports setting the In-Reply-To header
  via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line before the message body.
This is an external index of several public inboxes,
see mirroring instructions on how to clone and mirror
all data and code used by this external index.