From: Daniel J Walsh <dwalsh@redhat.com>
To: Yuichi Nakamura <himainu-ynakam@miomio.jp>
Cc: sds@epoch.ncsc.mil, selinux@tycho.nsa.gov
Subject: Re: idea: setfiles to exclude specific type
Date: Mon, 22 Nov 2004 12:00:34 -0500 [thread overview]
Message-ID: <41A21B32.8040808@redhat.com> (raw)
In-Reply-To: <200411221554.iAMFsPDM027086@mms-r01.iijmio.jp>
Yuichi Nakamura wrote:
>Hello.
>
>I add setfiles "-x" option.
>I attach my idea in "setfiles.diff".
>
>-x option is used to exclude specified type.
>
>For example,
># setfiles file_contexts /home -x httpd_user_rw_t
>setfiles skips relabeling files that have "httpd_user_rw_t".
>
>The reason why this option is necessary is following.
>I heard that fixfiles.cron is removed, because unwanted alerts are displayed.
>In some case, types must be preserved.
>http://www.redhat.com/archives/fedora-selinux-list/2004-November/msg00061.html
>
>But I think fixfiles.cron is useful, and hope it is included again.
>Because integrity of label is critical for SELinux.
>
>I think to suppress unwanted alerts,
>it is necessary to add new option in setfiles and modify fixfiles.
>
>Does it sound reasonable?
>
>---
>Yuichi Nakamura
>Japan SELinux Users Group(JSELUG)
>http://www.selinux.gr.jp/
>
>
Is there any way we could get a list of "variable policy" from the
loaded context? Or should we write a file with this in it.
IE, It would be nice to create an attribute (save_context???) That we
could assign to a file context, and have setfiles/restorcon ignore if a
file is se to this context? So httpd_???_context_rw_t, gpg_t,
ssh_key_t, user_tmp_t and others could be ignored if setfiles comes upon
them on a relabel or check?
I guess we could populate a context file via a grep during policy build.
Ideas?
Dan
--
This message was distributed to subscribers of the selinux mailing list.
If you no longer wish to subscribe, send mail to majordomo@tycho.nsa.gov with
the words "unsubscribe selinux" without quotes as the message.
next prev parent reply other threads:[~2004-11-22 17:00 UTC|newest]
Thread overview: 5+ messages / expand[flat|nested] mbox.gz Atom feed top
2004-11-22 15:54 idea: setfiles to exclude specific type Yuichi Nakamura
2004-11-22 17:00 ` Daniel J Walsh [this message]
2004-11-22 17:58 ` Yuichi Nakamura
2004-11-22 19:20 ` Colin Walters
2004-11-22 19:27 ` Daniel J Walsh
Reply instructions:
You may reply publicly to this message via plain-text email
using any one of the following methods:
* Save the following mbox file, import it into your mail client,
and reply-to-all from there: mbox
Avoid top-posting and favor interleaved quoting:
https://en.wikipedia.org/wiki/Posting_style#Interleaved_style
* Reply using the --to, --cc, and --in-reply-to
switches of git-send-email(1):
git send-email \
--in-reply-to=41A21B32.8040808@redhat.com \
--to=dwalsh@redhat.com \
--cc=himainu-ynakam@miomio.jp \
--cc=sds@epoch.ncsc.mil \
--cc=selinux@tycho.nsa.gov \
/path/to/YOUR_REPLY
https://kernel.org/pub/software/scm/git/docs/git-send-email.html
* If your mail client supports setting the In-Reply-To header
via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line
before the message body.
This is an external index of several public inboxes,
see mirroring instructions on how to clone and mirror
all data and code used by this external index.