From: "Christopher J. PeBenito" <cpebenito@tresys.com>
To: Kohei KaiGai <kaigai@kaigai.gr.jp>
Cc: <refpolicy@oss1.tresys.com>, SELinux-NSA <selinux@tycho.nsa.gov>
Subject: Re: [4/4] sepgsql -redefinition of use permission onto system objects
Date: Fri, 18 May 2012 14:20:19 -0400 [thread overview]
Message-ID: <4FB692E3.9050704@tresys.com> (raw)
In-Reply-To: <CADyhKSUNhZAbwKt+Qq7GJ2CxLs4dPqdDMEK666m4Gac_goejVw@mail.gmail.com>
On 05/11/12 09:17, Kohei KaiGai wrote:
> 2012/5/10 Christopher J. PeBenito <cpebenito@tresys.com>:
>> On 05/04/12 13:24, Kohei KaiGai wrote:
>>> 2012/5/4 Christopher J. PeBenito <cpebenito@tresys.com>:
>>>> On 05/04/12 09:33, Kohei KaiGai wrote:
>>>>> The patch 3 of 4 also required the 4 of 4 being refreshed to apply correctly.
>>>>> In addition, I forgot to allow sepgsql_admin_type to allow to "use" system
>>>>> objects.
>>>>>
>>>>> Please check the newer version. Thanks,
>>>>
>>>> Looks like the revised patch is missing.
>>>>
>>> Sorry, it is the attached one.
>>>
>>> Thanks,
>>
>> This one doesn't apply, the last hunk fails. I also had a problem with the 3rd patch, as the contrib hunk stopped it from applying too.
>>
> Sorry, I generated the series of patches based on the latest refpolicy and
> contrib tree.
>
> And, I added "0of4" patch that fixes bugs in MLS/MCS that I noticed during
> regression test efforts. MCS rules are defined twice for db_language class
> in spite of db_schema being forgotten, and "entrypoint" permission was not
> restricted at both of MCS / MLS policy.
>
> Here is no updates on part-1 ~ part-4 except for patch rebasing.
Merged.
--
Chris PeBenito
Tresys Technology, LLC
www.tresys.com | oss.tresys.com
--
This message was distributed to subscribers of the selinux mailing list.
If you no longer wish to subscribe, send mail to majordomo@tycho.nsa.gov with
the words "unsubscribe selinux" without quotes as the message.
WARNING: multiple messages have this Message-ID (diff)
From: cpebenito@tresys.com (Christopher J. PeBenito)
To: refpolicy@oss.tresys.com
Subject: [refpolicy] [4/4] sepgsql -redefinition of use permission onto system objects
Date: Fri, 18 May 2012 14:20:19 -0400 [thread overview]
Message-ID: <4FB692E3.9050704@tresys.com> (raw)
In-Reply-To: <CADyhKSUNhZAbwKt+Qq7GJ2CxLs4dPqdDMEK666m4Gac_goejVw@mail.gmail.com>
On 05/11/12 09:17, Kohei KaiGai wrote:
> 2012/5/10 Christopher J. PeBenito <cpebenito@tresys.com>:
>> On 05/04/12 13:24, Kohei KaiGai wrote:
>>> 2012/5/4 Christopher J. PeBenito <cpebenito@tresys.com>:
>>>> On 05/04/12 09:33, Kohei KaiGai wrote:
>>>>> The patch 3 of 4 also required the 4 of 4 being refreshed to apply correctly.
>>>>> In addition, I forgot to allow sepgsql_admin_type to allow to "use" system
>>>>> objects.
>>>>>
>>>>> Please check the newer version. Thanks,
>>>>
>>>> Looks like the revised patch is missing.
>>>>
>>> Sorry, it is the attached one.
>>>
>>> Thanks,
>>
>> This one doesn't apply, the last hunk fails. I also had a problem with the 3rd patch, as the contrib hunk stopped it from applying too.
>>
> Sorry, I generated the series of patches based on the latest refpolicy and
> contrib tree.
>
> And, I added "0of4" patch that fixes bugs in MLS/MCS that I noticed during
> regression test efforts. MCS rules are defined twice for db_language class
> in spite of db_schema being forgotten, and "entrypoint" permission was not
> restricted at both of MCS / MLS policy.
>
> Here is no updates on part-1 ~ part-4 except for patch rebasing.
Merged.
--
Chris PeBenito
Tresys Technology, LLC
www.tresys.com | oss.tresys.com
next prev parent reply other threads:[~2012-05-18 18:20 UTC|newest]
Thread overview: 14+ messages / expand[flat|nested] mbox.gz Atom feed top
2012-03-25 21:16 [4/4] sepgsql -redefinition of use permission onto system objects Kohei KaiGai
2012-03-25 21:16 ` [refpolicy] " Kohei KaiGai
2012-05-04 13:33 ` Kohei KaiGai
2012-05-04 13:33 ` [refpolicy] " Kohei KaiGai
2012-05-04 15:51 ` Christopher J. PeBenito
2012-05-04 15:51 ` [refpolicy] " Christopher J. PeBenito
2012-05-04 17:24 ` Kohei KaiGai
2012-05-04 17:24 ` [refpolicy] " Kohei KaiGai
2012-05-10 12:46 ` Christopher J. PeBenito
2012-05-10 12:46 ` [refpolicy] " Christopher J. PeBenito
2012-05-11 13:17 ` Kohei KaiGai
2012-05-11 13:17 ` [refpolicy] " Kohei KaiGai
2012-05-18 18:20 ` Christopher J. PeBenito [this message]
2012-05-18 18:20 ` Christopher J. PeBenito
Reply instructions:
You may reply publicly to this message via plain-text email
using any one of the following methods:
* Save the following mbox file, import it into your mail client,
and reply-to-all from there: mbox
Avoid top-posting and favor interleaved quoting:
https://en.wikipedia.org/wiki/Posting_style#Interleaved_style
* Reply using the --to, --cc, and --in-reply-to
switches of git-send-email(1):
git send-email \
--in-reply-to=4FB692E3.9050704@tresys.com \
--to=cpebenito@tresys.com \
--cc=kaigai@kaigai.gr.jp \
--cc=refpolicy@oss1.tresys.com \
--cc=selinux@tycho.nsa.gov \
/path/to/YOUR_REPLY
https://kernel.org/pub/software/scm/git/docs/git-send-email.html
* If your mail client supports setting the In-Reply-To header
via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line
before the message body.
This is an external index of several public inboxes,
see mirroring instructions on how to clone and mirror
all data and code used by this external index.