From: cpebenito@tresys.com (Christopher J. PeBenito)
To: refpolicy@oss.tresys.com
Subject: [refpolicy] [PATCH] [RFC] Fix strange file patterns
Date: Fri, 11 Apr 2014 11:03:04 -0400 [thread overview]
Message-ID: <53480428.8070200@tresys.com> (raw)
In-Reply-To: <CAPzO=Nz4y8i8HEcNo3BVM21Qoos_5m-pjb+Bf3b+R_7rzDarMA@mail.gmail.com>
Dan/Miroslav, do you have any feedback on these? They seem like reasonable changes to me.
On 04/08/2014 10:21 AM, Sven Vermeulen wrote:
> I'm OK with the changes. I am not aware of a finger implementation that uses a single character prefix to "fingerd" that would match the expression as well.
>
> With kind regard,
> Sven Vermeulen
>
> On Apr 5, 2014 10:38 PM, "Nicolas Iooss" <nicolas.iooss at m4x.org <mailto:nicolas.iooss@m4x.org>> wrote:
>
> Some file patterns look very strange, like:
>
> /var/log/cluster/.*\.*log
>
> I've found such patterns while writing a script that parses the file patterns.
> Hence I haven't tested if the new file contexts apply to the existing files.
> For example, this patch changes
>
> /var/run/*.fingerd\.pid
>
> to
>
> /var/run/fingerd\.pid
>
> because "/*" seems weird to me, but this also changes the semantic of the
> pattern. Another possibility which doesn't change the meaning is:
>
> /var/run/?.fingerd\.pid
>
> I send this patch as an RFC because what I consider abnormal may in fact be
> something expected or a workaround to fix some bugs I'm not aware of.
> ---
> finger.fc | 2 +-
> rhcs.fc | 2 +-
> setroubleshoot.fc | 2 +-
> 3 files changed, 3 insertions(+), 3 deletions(-)
>
> diff --git a/finger.fc b/finger.fc
> index 843940b..623421d 100644
> --- a/finger.fc
> +++ b/finger.fc
> @@ -7,4 +7,4 @@
>
> /var/log/cfingerd\.log.* -- gen_context(system_u:object_r:fingerd_log_t,s0)
>
> -/var/run/*.fingerd\.pid -- gen_context(system_u:object_r:fingerd_var_run_t,s0)
> +/var/run/fingerd\.pid -- gen_context(system_u:object_r:fingerd_var_run_t,s0)
> diff --git a/rhcs.fc b/rhcs.fc
> index 47de2d6..c619502 100644
> --- a/rhcs.fc
> +++ b/rhcs.fc
> @@ -14,7 +14,7 @@
>
> /var/lib/qdiskd(/.*)? gen_context(system_u:object_r:qdiskd_var_lib_t,s0)
>
> -/var/log/cluster/.*\.*log <<none>>
> +/var/log/cluster/.*\.log <<none>>
> /var/log/cluster/dlm_controld\.log.* -- gen_context(system_u:object_r:dlm_controld_var_log_t,s0)
> /var/log/cluster/fenced\.log.* -- gen_context(system_u:object_r:fenced_var_log_t,s0)
> /var/log/cluster/gfs_controld\.log.* -- gen_context(system_u:object_r:gfs_controld_var_log_t,s0)
> diff --git a/setroubleshoot.fc b/setroubleshoot.fc
> index 0b3a971..e89c06f 100644
> --- a/setroubleshoot.fc
> +++ b/setroubleshoot.fc
> @@ -1,6 +1,6 @@
> /usr/sbin/setroubleshootd -- gen_context(system_u:object_r:setroubleshootd_exec_t,s0)
>
> -/usr/share/setroubleshoot/SetroubleshootFixit\.py* -- gen_context(system_u:object_r:setroubleshoot_fixit_exec_t,s0)
> +/usr/share/setroubleshoot/SetroubleshootFixit\.py -- gen_context(system_u:object_r:setroubleshoot_fixit_exec_t,s0)
>
> /var/run/setroubleshoot(/.*)? gen_context(system_u:object_r:setroubleshoot_var_run_t,s0)
>
> --
> 1.9.1
--
Chris PeBenito
Tresys Technology, LLC
www.tresys.com | oss.tresys.com
next prev parent reply other threads:[~2014-04-11 15:03 UTC|newest]
Thread overview: 5+ messages / expand[flat|nested] mbox.gz Atom feed top
2014-04-05 20:37 [refpolicy] [PATCH] [RFC] Fix strange file patterns Nicolas Iooss
2014-04-08 14:21 ` Sven Vermeulen
2014-04-11 15:03 ` Christopher J. PeBenito [this message]
2014-04-11 15:11 ` Miroslav Grepl
2014-04-11 15:24 ` Christopher J. PeBenito
Reply instructions:
You may reply publicly to this message via plain-text email
using any one of the following methods:
* Save the following mbox file, import it into your mail client,
and reply-to-all from there: mbox
Avoid top-posting and favor interleaved quoting:
https://en.wikipedia.org/wiki/Posting_style#Interleaved_style
* Reply using the --to, --cc, and --in-reply-to
switches of git-send-email(1):
git send-email \
--in-reply-to=53480428.8070200@tresys.com \
--to=cpebenito@tresys.com \
--cc=refpolicy@oss.tresys.com \
/path/to/YOUR_REPLY
https://kernel.org/pub/software/scm/git/docs/git-send-email.html
* If your mail client supports setting the In-Reply-To header
via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line
before the message body.
This is an external index of several public inboxes,
see mirroring instructions on how to clone and mirror
all data and code used by this external index.