All of lore.kernel.org
 help / color / mirror / Atom feed
* [refpolicy] Transition unconfined users to dpkg_t domain
@ 2014-01-07 12:29 Laurent Bigonville
       [not found] ` <CAPzO=NxbnkP-M-GJhDxW4w=5q7Q6xWgG=m3J1p09ETTs-HuzNw@mail.gmail.com>
  0 siblings, 1 reply; 27+ messages in thread
From: Laurent Bigonville @ 2014-01-07 12:29 UTC (permalink / raw)
  To: refpolicy

Hello,

Currently in the refpolicy unconfined users can transition to the rpm_t
(and then to rpm_script_t) domain when using the rpm commands.

On the other hand, the transition is not allowed for unconfined users
to transition to dpkg_t. Shouldn't also be the case?

I can propose a patch if you want, but I prefer to ask first as I know
there are some discussion about transitioning users out of the
unconfined domain.

Also, since 1.17.0, dpkg is transitioning maintainer scripts to the
dpkg_script_t domain. Unfortunately the dpkg-reconfigure script (which
is in perl) is not doing so. An idea how this should be done? I've
opened [0] is somebody is interested.

Cheers,

Laurent Bigonville

[0] http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=732845

^ permalink raw reply	[flat|nested] 27+ messages in thread

end of thread, other threads:[~2014-01-13 12:35 UTC | newest]

Thread overview: 27+ messages (download: mbox.gz follow: Atom feed
-- links below jump to the message on this page --
2014-01-07 12:29 [refpolicy] Transition unconfined users to dpkg_t domain Laurent Bigonville
     [not found] ` <CAPzO=NxbnkP-M-GJhDxW4w=5q7Q6xWgG=m3J1p09ETTs-HuzNw@mail.gmail.com>
     [not found]   ` <20140107181207.13f8826d@soldur.bigon.be>
2014-01-09 12:24     ` Laurent Bigonville
2014-01-09 13:46       ` Dominick Grift
2014-01-09 15:57         ` Laurent Bigonville
2014-01-09 16:12           ` Dominick Grift
2014-01-09 16:19             ` Laurent Bigonville
2014-01-09 16:36               ` Dominick Grift
2014-01-09 20:26                 ` Daniel J Walsh
2014-01-09 20:32                   ` Stephen Smalley
2014-01-10 11:47                     ` Laurent Bigonville
2014-01-10 13:49                       ` Daniel J Walsh
2014-01-10 14:51                       ` Stephen Smalley
2014-01-10 14:59                         ` Daniel J Walsh
2014-01-10 17:27                         ` Laurent Bigonville
2014-01-10 17:37                           ` Stephen Smalley
2014-01-10 18:39                             ` Sven Vermeulen
2014-01-10 18:40                               ` Stephen Smalley
2014-01-10 18:46                                 ` Sven Vermeulen
2014-01-10 19:19                                   ` Dominick Grift
2014-01-12  0:59                                     ` Russell Coker
2014-01-12 12:23                                       ` Dominick Grift
2014-01-13 12:35                                         ` Russell Coker
2014-01-10 18:52                                 ` Dominick Grift
2014-01-10 19:58                                   ` Stephen Smalley
2014-01-12  1:04                                   ` Russell Coker
2014-01-12 12:25                                     ` Dominick Grift
2014-01-12 12:20                                 ` Laurent Bigonville

This is an external index of several public inboxes,
see mirroring instructions on how to clone and mirror
all data and code used by this external index.