From: dwalsh@redhat.com (Daniel J Walsh)
To: refpolicy@oss.tresys.com
Subject: [refpolicy] services_avahi.patch and services_dbus.patch
Date: Thu, 20 Nov 2008 10:22:15 -0500 [thread overview]
Message-ID: <492580A7.1000209@redhat.com> (raw)
-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA1
http://people.fedoraproject.org/~dwalsh/SELinux/F11/services_avahi.patch
Added avahi_signull and avahi_initrc_domtrans both used by networkmanager
Also allow avahi to search var_lib and avahi is now started by dbus.
http://people.fedoraproject.org/~dwalsh/SELinux/F11/services_dbus.patch
dbus needs to be ranged.
Fix system_dbusd_var_lib_t definition.
dbus needs getcap and setpgid
dbus can exec itself.
Lists inotify
dbus can be used to start initrc scripts and random binaries so needs to
transition to initrc_t. Probably should be blocked on mls machines.
Starts networkmanager, add dbus unconfiend
-----BEGIN PGP SIGNATURE-----
Version: GnuPG v1.4.9 (GNU/Linux)
Comment: Using GnuPG with Fedora - http://enigmail.mozdev.org
iEYEARECAAYFAkklgKcACgkQrlYvE4MpobNhwwCg1UlOZrS42vEEvkl0DSPRW4R4
S/MAoKDXPrQe+fZJkMgx3JaQhPJSrjRK
=DK63
-----END PGP SIGNATURE-----
reply other threads:[~2008-11-20 15:22 UTC|newest]
Thread overview: [no followups] expand[flat|nested] mbox.gz Atom feed
Reply instructions:
You may reply publicly to this message via plain-text email
using any one of the following methods:
* Save the following mbox file, import it into your mail client,
and reply-to-all from there: mbox
Avoid top-posting and favor interleaved quoting:
https://en.wikipedia.org/wiki/Posting_style#Interleaved_style
* Reply using the --to, --cc, and --in-reply-to
switches of git-send-email(1):
git send-email \
--in-reply-to=492580A7.1000209@redhat.com \
--to=dwalsh@redhat.com \
--cc=refpolicy@oss.tresys.com \
/path/to/YOUR_REPLY
https://kernel.org/pub/software/scm/git/docs/git-send-email.html
* If your mail client supports setting the In-Reply-To header
via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line
before the message body.
This is an external index of several public inboxes,
see mirroring instructions on how to clone and mirror
all data and code used by this external index.