From: Ivan Gyurdiev <ivg2@cornell.edu>
To: Stephen Smalley <sds@tycho.nsa.gov>
Cc: Daniel J Walsh <dwalsh@redhat.com>,
SELinux-dev@tresys.com, Joshua Brindle <jbrindle@tresys.com>,
SE Linux <selinux@tycho.nsa.gov>
Subject: Re: rawhide targeted vs. refpolicy rpm
Date: Wed, 16 Nov 2005 09:08:19 -0500 [thread overview]
Message-ID: <437B3D53.1090401@cornell.edu> (raw)
In-Reply-To: <1132148567.12540.28.camel@moss-spartans.epoch.ncsc.mil>
>> One thing I am still not clear about is why we need a labeling prefix
>> that's not related to a role.. how is targeted using the system role,
>> and labeling things with the user prefix? Isn't the whole point of the
>> labeling prefix to prevent that type of thing (cross-role communication).
>>
>
> Targeted policy has no notion of user roles/domains. There is
> effectively only one SELinux user identity and role in targeted policy;
> the others are purely for compatibility with strict policy in file
> contexts and application configuration files. Targeted policy only uses
> TE domains to confine particular processes.
>
So why don't we label files in targeted as system_home_t, which seems
more correct and workaround this issue. The only change that seems
necessary to me is to move the defrole functions from sepol and into
semanage, since they don't do anything in sepol, and are misleading -
that would be additive divergence on the semanage side. If the user
wants to query sepol, and write records into semanage, he/she would have
to set the default role in addition to the other data.
--
This message was distributed to subscribers of the selinux mailing list.
If you no longer wish to subscribe, send mail to majordomo@tycho.nsa.gov with
the words "unsubscribe selinux" without quotes as the message.
next prev parent reply other threads:[~2005-11-16 14:08 UTC|newest]
Thread overview: 30+ messages / expand[flat|nested] mbox.gz Atom feed top
[not found] <BF9A263D.7FFA%csellers@tresys.com>
[not found] ` <4374BDEC.4050600@redhat.com>
[not found] ` <200511111717.16542.csellers@tresys.com>
[not found] ` <200511141041.49643.csellers@tresys.com>
[not found] ` <1131983537.5415.137.camel@moss-spartans.epoch.ncsc.mil>
2005-11-14 16:17 ` rawhide targeted vs. refpolicy rpm Daniel J Walsh
2005-11-14 16:51 ` Stephen Smalley
2005-11-14 18:23 ` Daniel J Walsh
2005-11-14 19:32 ` Stephen Smalley
2005-11-15 13:23 ` Stephen Smalley
2005-11-14 16:59 ` Joshua Brindle
2005-11-14 18:27 ` Daniel J Walsh
2005-11-14 19:37 ` Stephen Smalley
2005-11-15 11:17 ` Stephen Smalley
2005-11-15 13:40 ` Stephen Smalley
2005-11-15 14:44 ` Daniel J Walsh
2005-11-15 14:57 ` Stephen Smalley
2005-11-15 15:10 ` Stephen Smalley
2005-11-15 15:18 ` Stephen Smalley
2005-11-15 19:03 ` Stephen Smalley
2005-11-15 19:28 ` Joshua Brindle
2005-11-16 13:12 ` Stephen Smalley
2005-11-15 19:50 ` Ivan Gyurdiev
2005-11-16 13:11 ` Stephen Smalley
2005-11-16 13:42 ` Ivan Gyurdiev
2005-11-16 13:42 ` Stephen Smalley
2005-11-16 14:08 ` Ivan Gyurdiev [this message]
2005-11-16 14:14 ` Stephen Smalley
2005-11-16 14:27 ` Ivan Gyurdiev
2005-11-16 14:26 ` Stephen Smalley
2005-11-16 14:47 ` Ivan Gyurdiev
2005-11-16 14:53 ` Ivan Gyurdiev
2005-11-14 17:28 ` Ivan Gyurdiev
2005-11-14 18:09 ` I have modified Joshua's libsemanage-swigify patch to work better in my spec file Daniel J Walsh
2005-11-15 13:21 ` Stephen Smalley
Reply instructions:
You may reply publicly to this message via plain-text email
using any one of the following methods:
* Save the following mbox file, import it into your mail client,
and reply-to-all from there: mbox
Avoid top-posting and favor interleaved quoting:
https://en.wikipedia.org/wiki/Posting_style#Interleaved_style
* Reply using the --to, --cc, and --in-reply-to
switches of git-send-email(1):
git send-email \
--in-reply-to=437B3D53.1090401@cornell.edu \
--to=ivg2@cornell.edu \
--cc=SELinux-dev@tresys.com \
--cc=dwalsh@redhat.com \
--cc=jbrindle@tresys.com \
--cc=sds@tycho.nsa.gov \
--cc=selinux@tycho.nsa.gov \
/path/to/YOUR_REPLY
https://kernel.org/pub/software/scm/git/docs/git-send-email.html
* If your mail client supports setting the In-Reply-To header
via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line
before the message body.
This is an external index of several public inboxes,
see mirroring instructions on how to clone and mirror
all data and code used by this external index.