From: Daniel Burgener <dburgener@linux.microsoft.com>
To: Russell Coker <russell@coker.com.au>, selinux-refpolicy@vger.kernel.org
Subject: Re: [PATCH] strict patches
Date: Tue, 12 Jan 2021 09:18:42 -0500 [thread overview]
Message-ID: <9e38ca3b-cc76-2b52-dcd5-01c661cdcfcd@linux.microsoft.com> (raw)
In-Reply-To: <40e12eb0-782d-2a73-3cd9-a2e2cca2d916@linux.microsoft.com>
On 1/12/21 9:15 AM, Daniel Burgener wrote:
> On 1/12/21 5:31 AM, Russell Coker wrote:
>> Also remove the systemd_analyze_t domain which
>> does no good.
>
> I proposed this same change on github:
> https://github.com/SELinuxProject/refpolicy/pull/321
>
> The consensus there was that having a separate domain for this access
> would add value and the better direction would be to flesh out the
> permissions it needs. We have a bit of a starting point locally on
> that. I'm not sure what shape it's in with regard to upstreaming, but
> I'll talk to the developer who worked on it.
>
> -Daniel
My mistake - looks like we ended up granting the needed permissions to
the parent domain in our environment, so I don't have any
systemd-analyze policy available for upstream. I still might try
developing some, but I don't expect that I'm likely to get to it soon.
-Daniel
prev parent reply other threads:[~2021-01-12 14:19 UTC|newest]
Thread overview: 3+ messages / expand[flat|nested] mbox.gz Atom feed top
2021-01-12 10:31 [PATCH] strict patches Russell Coker
2021-01-12 14:15 ` Daniel Burgener
2021-01-12 14:18 ` Daniel Burgener [this message]
Reply instructions:
You may reply publicly to this message via plain-text email
using any one of the following methods:
* Save the following mbox file, import it into your mail client,
and reply-to-all from there: mbox
Avoid top-posting and favor interleaved quoting:
https://en.wikipedia.org/wiki/Posting_style#Interleaved_style
* Reply using the --to, --cc, and --in-reply-to
switches of git-send-email(1):
git send-email \
--in-reply-to=9e38ca3b-cc76-2b52-dcd5-01c661cdcfcd@linux.microsoft.com \
--to=dburgener@linux.microsoft.com \
--cc=russell@coker.com.au \
--cc=selinux-refpolicy@vger.kernel.org \
/path/to/YOUR_REPLY
https://kernel.org/pub/software/scm/git/docs/git-send-email.html
* If your mail client supports setting the In-Reply-To header
via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line
before the message body.
This is an external index of several public inboxes,
see mirroring instructions on how to clone and mirror
all data and code used by this external index.