From mboxrd@z Thu Jan 1 00:00:00 1970 From: Paul Moore Subject: Re: [RFC][PATCH] selinux: Report result in avc messages Date: Thu, 01 May 2014 15:09:43 -0400 Message-ID: <4012781.FYeZg7nLGc@sifl> References: <32537239.2TmFnM48BI@x2> Mime-Version: 1.0 Content-Type: text/plain; charset="us-ascii" Content-Transfer-Encoding: 7bit Return-path: Received: from mx1.redhat.com (ext-mx16.extmail.prod.ext.phx2.redhat.com [10.5.110.21]) by int-mx13.intmail.prod.int.phx2.redhat.com (8.14.4/8.14.4) with ESMTP id s41J9nBn020028 for ; Thu, 1 May 2014 15:09:49 -0400 Received: from mail-qa0-f50.google.com (mail-qa0-f50.google.com [209.85.216.50]) by mx1.redhat.com (8.14.4/8.14.4) with ESMTP id s41J9kua012715 for ; Thu, 1 May 2014 15:09:48 -0400 Received: by mail-qa0-f50.google.com with SMTP id s7so3391248qap.9 for ; Thu, 01 May 2014 12:09:46 -0700 (PDT) In-Reply-To: List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , Sender: linux-audit-bounces@redhat.com Errors-To: linux-audit-bounces@redhat.com To: selinux@tycho.nsa.gov Cc: linux-audit@redhat.com List-Id: linux-audit@redhat.com On Wednesday, April 30, 2014 09:08:28 AM Stephen Smalley wrote: > The revised patch switched from result=allowed|denied to > permissive=0|1 in the avc message. I think Bill's point was with > respect to the code, which still internally is passing around the > result of the decision and inferring the permissive state from it, > rather than the output string itself. I'm fine with this patch, but before I merge it for next I just wanted to make sure there isn't another revision coming? -- paul moore www.paul-moore.com