From: Joshua Brindle <method@gentoo.org>
To: russell@coker.com.au
Cc: SE-Linux <selinux@tycho.nsa.gov>, Daniel Walsh <dwalsh@redhat.com>
Subject: Re: FC5 policy
Date: Sat, 23 Sep 2006 19:58:10 -0400 [thread overview]
Message-ID: <4515CA12.3050107@gentoo.org> (raw)
In-Reply-To: <200609240813.56907.russell@coker.com.au>
Russell Coker wrote:
> On Sunday 24 September 2006 00:54, Joshua Brindle <method@gentoo.org> wrote:
>
>> Russell Coker wrote:
>>
>>> http://www.coker.com.au/selinux/fc5/
>>>
>>> At the above URL I have my latest packages of FC5 policy with patch and
>>> source. They compile the policy with amavis and clamav policy in base
>>> (which can't be included in an FC5 update as the tools are broken and
>>> don't support policy moving from a module to base), they have Postgrey
>>> policy compiled in, and they have a few other policy changes (such as
>>> allowing unconfined_t to kill unlabeled_t processes).
>>>
>> um? in what way are the tools broken? It is quite easy to move a module
>> to base:
>>
>> semodule -r clamav -i base-with-clamav.pp
>>
>
> The package installation process can't do it.
>
sounds like a problem with the package manager rather than the selinux
tools.
> Ideally we would have some way for semodule to automatically figure out that
> base-with-clamav.pp has the clamav module and do the right thing.
>
>
doubtful. What if they have different rules? How about slightly
different type spaces? Is it ok if some types are invalided as long as
some aren't? This is certainly not something semodule should do.
>>> Also my patch removes some unnecessary and inappropriate access from some
>>> domains. I know that most people don't like removing access from
>>> processes, but I think we need to use the principle of least-privilege
>>> more seriously.
>>>
>> Who doesn't like removing access from processes? I think we are all on
>> the same side here..
>>
>
> Then why do I keep sending this patch to the list and it doesn't get applied?
>
> Why hasn't the pre-fedora /boot sym-links thing been cleaned up?
>
i didn't see you send any patch to the list. you sent a link to some
packages and some backhanded remarks about the policy, certainly not a
good way to get something merged..
--
This message was distributed to subscribers of the selinux mailing list.
If you no longer wish to subscribe, send mail to majordomo@tycho.nsa.gov with
the words "unsubscribe selinux" without quotes as the message.
next prev parent reply other threads:[~2006-09-24 0:00 UTC|newest]
Thread overview: 8+ messages / expand[flat|nested] mbox.gz Atom feed top
2006-09-23 14:34 FC5 policy Russell Coker
2006-09-23 14:54 ` Joshua Brindle
2006-09-23 22:13 ` Russell Coker
2006-09-23 23:58 ` Joshua Brindle [this message]
2006-09-24 0:31 ` Russell Coker
2006-09-24 1:02 ` Joshua Brindle
2006-09-25 17:57 ` Christopher J. PeBenito
-- strict thread matches above, loose matches on Subject: below --
2006-07-16 3:32 Russell Coker
Reply instructions:
You may reply publicly to this message via plain-text email
using any one of the following methods:
* Save the following mbox file, import it into your mail client,
and reply-to-all from there: mbox
Avoid top-posting and favor interleaved quoting:
https://en.wikipedia.org/wiki/Posting_style#Interleaved_style
* Reply using the --to, --cc, and --in-reply-to
switches of git-send-email(1):
git send-email \
--in-reply-to=4515CA12.3050107@gentoo.org \
--to=method@gentoo.org \
--cc=dwalsh@redhat.com \
--cc=russell@coker.com.au \
--cc=selinux@tycho.nsa.gov \
/path/to/YOUR_REPLY
https://kernel.org/pub/software/scm/git/docs/git-send-email.html
* If your mail client supports setting the In-Reply-To header
via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line
before the message body.
This is an external index of several public inboxes,
see mirroring instructions on how to clone and mirror
all data and code used by this external index.