From: Dominick Grift <dac.override@gmail.com>
To: Stephen Smalley <sds@tycho.nsa.gov>, selinux@tycho.nsa.gov
Subject: Re: continuation of systemd/SELinux discussion from Github
Date: Wed, 2 Dec 2015 22:37:46 +0100 [thread overview]
Message-ID: <20151202213745.GE1028@x250> (raw)
In-Reply-To: <20151202194715.GC1028@x250>
-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA512
On Wed, Dec 02, 2015 at 08:47:15PM +0100, Dominick Grift wrote:
>
> Those are good questions but i do not see how they are directly related
> to the question whether systemd --user should be a selinux user space object
> manager or not (in my view it obviously should but i am not trusted by
> systemd maintainers, walsh is trusted and walsh gave systemd maintainers
> the impression that systemd --user does not have to be an selinux object
> manager) I strongly suspect that is wrong.
>
The problem is that i sincerely do not know what to do, and i am worried
about this. I would like confirmation about whether or not systemd
- --user needs to be an object manager for consistency in selinux enabled
systems.
If someone can tell me with confidence that it does not then i will
accept that. If someone can tell me with confidence that systemd --user
needs to be an user space object manager because else it will "break
selinux" then I am worried that redhat will not acknowledge that simply
because its not on their agenda.
It is going to take a long time before redhat will be able to produce
any half useful support for systemd --user for confined users, and even
when they get to that point i am afraid they will still leave that gap
simply because i am afraid that its not an priority to them.
In the mean time we might be stuck with this inconsistency.
All Mr. Walsh had to do was tell Mr. Poettering. Hold that commit for
now while i double check whether its desired or not. Instead he gave the
go-ahead to remove code I rely on in a blink of an eye.
If he was right by determining that systemd --user does not need to be
an selinux object manager then i will apologize to him.
If it turns out that it really did not make sense for him to support the
removal of that code then i am sincerely disappointed.
02DFF788
4D30 903A 1CF3 B756 FB48 1514 3148 83A2 02DF F788
https://sks-keyservers.net/pks/lookup?op=get&search=0x314883A202DFF788
Dominick Grift
-----BEGIN PGP SIGNATURE-----
Version: GnuPG v2
iQGcBAEBCgAGBQJWX2SlAAoJENAR6kfG5xmcvd0L/1ZQP0uJoo931bXDIulR/xaY
eH6cPytluJVETS9gNiQTFYVTIIWUdegjaDbE0cW/sHJCHiBcksPc9fXlv30vC4CL
wad26KVMsRZLydxmM/K9IKak/AtRSu4tqmWK/UqXhBOGqMDWLYCJzcSebTC3w/wY
+GlxBMuSczN1a6iSYUSak1fyn47SC1hekGIcd7HE3KEzqI1e+lodC+npV/fn0a6D
9uefujVZZxGM8jxQcU1zaT0SoLNjC8UTMsGXRLc7BRkbE1OgJsE8xIkekPOGSw6k
dsGC4WUMbC+ExU0gLltprdgmpxJpIMsI9jy8yO6PqXaEwbk0MxTcA2OlafChhfJ9
yG0f5cfG6NW3CDQmVf/6WOYzqfE/KAaq8VomPpNRb2HXDPRnOIPbTuSLmMhSGBsB
FuSmuKasrdE+XzfWOE3PM+XkpsDg5QJVsuyP8+t+hcSuSE1oqZeoXflhe5CZtJL8
ma8tHOsZvWG2MzqY17NPgcEZMlqixWeebX+zQUVabA==
=uhHm
-----END PGP SIGNATURE-----
next prev parent reply other threads:[~2015-12-02 21:37 UTC|newest]
Thread overview: 17+ messages / expand[flat|nested] mbox.gz Atom feed top
2015-12-02 10:18 continuation of systemd/SELinux discussion from Github Dominick Grift
2015-12-02 10:31 ` Dominick Grift
2015-12-02 18:20 ` Stephen Smalley
2015-12-02 19:47 ` Dominick Grift
2015-12-02 21:23 ` Stephen Smalley
2015-12-02 21:42 ` Dominick Grift
2015-12-03 16:02 ` Miroslav Grepl
2015-12-03 16:11 ` Stephen Smalley
2015-12-03 17:30 ` Dominick Grift
2015-12-04 15:55 ` Dominick Grift
2015-12-10 9:21 ` Miroslav Grepl
2015-12-03 16:30 ` Dominick Grift
2015-12-03 17:20 ` Dominick Grift
2015-12-03 20:25 ` Dominick Grift
2015-12-02 21:37 ` Dominick Grift [this message]
2015-12-02 20:34 ` Dominick Grift
2015-12-03 9:09 ` Laurent Bigonville
Reply instructions:
You may reply publicly to this message via plain-text email
using any one of the following methods:
* Save the following mbox file, import it into your mail client,
and reply-to-all from there: mbox
Avoid top-posting and favor interleaved quoting:
https://en.wikipedia.org/wiki/Posting_style#Interleaved_style
* Reply using the --to, --cc, and --in-reply-to
switches of git-send-email(1):
git send-email \
--in-reply-to=20151202213745.GE1028@x250 \
--to=dac.override@gmail.com \
--cc=sds@tycho.nsa.gov \
--cc=selinux@tycho.nsa.gov \
/path/to/YOUR_REPLY
https://kernel.org/pub/software/scm/git/docs/git-send-email.html
* If your mail client supports setting the In-Reply-To header
via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line
before the message body.
This is an external index of several public inboxes,
see mirroring instructions on how to clone and mirror
all data and code used by this external index.