All of lore.kernel.org
 help / color / mirror / Atom feed
* Allow audit2allow to return constraint information from policy
@ 2013-10-24 13:28 Daniel J Walsh
  2013-10-24 16:02 ` Dominick Grift
  2013-10-25 17:35 ` Stephen Smalley
  0 siblings, 2 replies; 4+ messages in thread
From: Daniel J Walsh @ 2013-10-24 13:28 UTC (permalink / raw)
  To: SELinux

[-- Attachment #1: Type: text/plain, Size: 1274 bytes --]

-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA1

At the end of last year I was complaining about audit2allow and the SELinux
tools chain not being able to give better information about what constraint is
being violated, so a admin or policy writer could have a clue on how to fix
the problem.

A fairly common problem is domains trying to change the role or user component
of the label.  Or in the MCS and MLS world, what attribute do I need to add to
my policy to allow the AVC.

Richard Haines wrote some nice patches to add the constraint information to
the kernel and to change user space to reveal this information.

Sadly we thought these discussions had happened on the list, but I guess we
had taken it private.  Here is the userspace patch to reveal this information.

The kernel team will be posting the kernel patch hopefully soon.  We believe
that even though the kernel does not need the additional information about the
constraint, the limited space required to carry this information makes sense.

-----BEGIN PGP SIGNATURE-----
Version: GnuPG v1.4.15 (GNU/Linux)
Comment: Using GnuPG with Thunderbird - http://www.enigmail.net/

iEYEARECAAYFAlJpIHwACgkQrlYvE4MpobM6vgCg3IoQr5tlM8NVgT/pId2QpKrz
E5gAoInxyCNAOQuXA1M6Z1YX36U9y31u
=3Ern
-----END PGP SIGNATURE-----

[-- Warning: decoded text below may be mangled, UTF-8 assumed --]
[-- Attachment #2: 0001-Richard-Haines-patch-that-allows-us-discover-constra.patch --]
[-- Type: text/x-patch; name="0001-Richard-Haines-patch-that-allows-us-discover-constra.patch", Size: 0 bytes --]



^ permalink raw reply	[flat|nested] 4+ messages in thread

end of thread, other threads:[~2013-10-25 17:35 UTC | newest]

Thread overview: 4+ messages (download: mbox.gz follow: Atom feed
-- links below jump to the message on this page --
2013-10-24 13:28 Allow audit2allow to return constraint information from policy Daniel J Walsh
2013-10-24 16:02 ` Dominick Grift
2013-10-24 16:40   ` Daniel J Walsh
2013-10-25 17:35 ` Stephen Smalley

This is an external index of several public inboxes,
see mirroring instructions on how to clone and mirror
all data and code used by this external index.