All of lore.kernel.org
 help / color / mirror / Atom feed
* [refpolicy] network: Enable "network_peer_controls" and fix some remaining issues
@ 2009-01-16 22:08 Paul Moore
       [not found] ` <1233326781.6143.9.camel@defiant.pebenito.net>
  0 siblings, 1 reply; 2+ messages in thread
From: Paul Moore @ 2009-01-16 22:08 UTC (permalink / raw)
  To: refpolicy

An embedded and charset-unspecified text was scrubbed...
Name: network-in_out_basic
Url: http://oss.tresys.com/pipermail/refpolicy/attachments/20090116/39b08e75/attachment.pl 

^ permalink raw reply	[flat|nested] 2+ messages in thread

* [refpolicy] network: Enable "network_peer_controls" and fix some remaining issues
       [not found] ` <1233326781.6143.9.camel@defiant.pebenito.net>
@ 2009-02-02 22:16   ` Paul Moore
  0 siblings, 0 replies; 2+ messages in thread
From: Paul Moore @ 2009-02-02 22:16 UTC (permalink / raw)
  To: refpolicy

On Friday 30 January 2009 9:46:21 am you wrote:
> On Fri, 2009-01-16 at 17:08 -0500, Paul Moore wrote:
> > plain text document attachment (network-in_out_basic)
> > We added the network_peer_controls capability back in Linux Kernel
> > 2.6.25 but didn't activate the capability because more work was
> > needed to ensure a smooth transition to the new controls.  This
> > patch enables the network_peer_controls capability and fixes a few
> > remaining issues with its use.  With this patch applied to the
> > Fedora Rawhide SELinux policy (selinux-policy-3.6.1-4.fc11) I am
> > able to interact with the machine over the network without any new
> > AVC denials.
>
> Does it work without the legacy support rules?  I'm thinking that for
> now we don't want the legacy support in these interfaces, since we're
> still not ready to dump all the compat_net support.  Then its clear
> that its not supposed to be used for compat_net rules.

I'm testing it right now (it should work without the legacy bits).  Once 
I've verified the changes I'll repost.

-- 
paul moore
linux @ hp

^ permalink raw reply	[flat|nested] 2+ messages in thread

end of thread, other threads:[~2009-02-02 22:16 UTC | newest]

Thread overview: 2+ messages (download: mbox.gz follow: Atom feed
-- links below jump to the message on this page --
2009-01-16 22:08 [refpolicy] network: Enable "network_peer_controls" and fix some remaining issues Paul Moore
     [not found] ` <1233326781.6143.9.camel@defiant.pebenito.net>
2009-02-02 22:16   ` Paul Moore

This is an external index of several public inboxes,
see mirroring instructions on how to clone and mirror
all data and code used by this external index.