All of lore.kernel.org
 help / color / mirror / Atom feed
* SELinux file context matching
@ 2016-02-02 17:48 Mark Steele
  2016-02-02 18:15 ` Stephen Smalley
  0 siblings, 1 reply; 5+ messages in thread
From: Mark Steele @ 2016-02-02 17:48 UTC (permalink / raw)
  To: selinux

[-- Attachment #1: Type: text/plain, Size: 1142 bytes --]

Hi list,

I've got some file contexts setup for an application, and can't get the
file context matching to work as I would expect.

[root@dev1 policy]# cat /etc/selinux/targeted/contexts/files/file_contexts
| grep cinched
/etc/cinched(/.*)?      system_u:object_r:ts_etc_t:s0
/var/log/cinched(/.*)?  system_u:object_r:ts_log_t:s0
/var/lib/cinched(/.*)?  system_u:object_r:ts_t:s0
*/usr/lib64/cinched(/.*)?        system_u:object_r:ts_lib_t:s0*
/etc/bash_completion.d/cinched_bash_completions
system_u:object_r:ts_etc_t:s0
/var/log/cinched/audit(/.*)?    system_u:object_r:ts_audit_log_t:s0
/usr/sbin/cinched       system_u:object_r:ts_exec_t:s0

[root@dev1 policy]# matchpathcon /usr/lib64/cinched/
*/usr/lib64/cinched      system_u:object_r:lib_t:s0*

[root@dev1 policy]# findcon
/etc/selinux/targeted/contexts/files/file_contexts -p /usr/lib64/cinched
/.*             system_u:object_r:default_t:s0
/usr/.*         system_u:object_r:usr_t:s0
*/usr/lib64/cinched(/.*)?                system_u:object_r:ts_lib_t:s0*


This is running on CentOS 7. I was assuming that since my rule has the
longest stem, it would be applied.

Any suggestions?

[-- Attachment #2: Type: text/html, Size: 1717 bytes --]

^ permalink raw reply	[flat|nested] 5+ messages in thread

end of thread, other threads:[~2016-02-02 20:46 UTC | newest]

Thread overview: 5+ messages (download: mbox.gz follow: Atom feed
-- links below jump to the message on this page --
2016-02-02 17:48 SELinux file context matching Mark Steele
2016-02-02 18:15 ` Stephen Smalley
2016-02-02 18:26   ` Jason Zaman
2016-02-02 18:31   ` Mike Palmiotto
2016-02-02 20:45     ` Mark Steele

This is an external index of several public inboxes,
see mirroring instructions on how to clone and mirror
all data and code used by this external index.