2008-09-24 20:30:58

by Daniel Walsh

[permalink] [raw]
Subject: [refpolicy] services_automount.patch

-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA1

http://people.fedoraproject.org/~dwalsh/SELinux/F10/services_automount.patch

Add initrc script support

allow admin to start/stop service

Admin needs admin_pattern on all file types

Additional files in /var/run need correct label

creates a fifo_file in /var/run

read/write autofs device

uses fuse devices

calls getpw* so needs auth_use_nsswitch

users kerberos keytab files

searches nfs state

can manipulate samba files

-----BEGIN PGP SIGNATURE-----
Version: GnuPG v1.4.9 (GNU/Linux)
Comment: Using GnuPG with Fedora - http://enigmail.mozdev.org

iEYEARECAAYFAkjao4IACgkQrlYvE4MpobMHSwCg1ZREHdBQ16pGs0WgSMJEGVEF
58cAoMvPGg0a7xMrB6CRCLezXrL4Gwfz
=wFdD
-----END PGP SIGNATURE-----


2008-10-08 20:07:04

by cpebenito

[permalink] [raw]
Subject: [refpolicy] services_automount.patch

On Wed, 2008-09-24 at 16:30 -0400, Daniel J Walsh wrote:
> http://people.fedoraproject.org/~dwalsh/SELinux/F10/services_automount.patch
>
> Add initrc script support
>
> allow admin to start/stop service
>
> Admin needs admin_pattern on all file types
>
> Additional files in /var/run need correct label
>
> creates a fifo_file in /var/run
>
> read/write autofs device
>
> uses fuse devices
>
> calls getpw* so needs auth_use_nsswitch
>
> users kerberos keytab files
>
> searches nfs state
>
> can manipulate samba files

Merged except for the dev_rw_autofs()

--
Chris PeBenito
Tresys Technology, LLC
(410) 290-1411 x150

2008-10-09 01:51:42

by Daniel Walsh

[permalink] [raw]
Subject: [refpolicy] services_automount.patch

-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA1

Christopher J. PeBenito wrote:
> On Wed, 2008-09-24 at 16:30 -0400, Daniel J Walsh wrote:
>> http://people.fedoraproject.org/~dwalsh/SELinux/F10/services_automount.patch
>>
>> Add initrc script support
>>
>> allow admin to start/stop service
>>
>> Admin needs admin_pattern on all file types
>>
>> Additional files in /var/run need correct label
>>
>> creates a fifo_file in /var/run
>>
>> read/write autofs device
>>
>> uses fuse devices
>>
>> calls getpw* so needs auth_use_nsswitch
>>
>> users kerberos keytab files
>>
>> searches nfs state
>>
>> can manipulate samba files
>
> Merged except for the dev_rw_autofs()
>
Added automount device patch
-----BEGIN PGP SIGNATURE-----
Version: GnuPG v1.4.9 (GNU/Linux)
Comment: Using GnuPG with Fedora - http://enigmail.mozdev.org

iEYEARECAAYFAkjtY64ACgkQrlYvE4MpobMBZgCfYfwzrHRIUGhLWUumcuBwuv/A
P8wAn368sNS0d1oRnYrk4nx4FCtB1Zc6
=zlQq
-----END PGP SIGNATURE-----
-------------- next part --------------
An embedded and charset-unspecified text was scrubbed...
Name: services_automount.patch
Url: http://oss.tresys.com/pipermail/refpolicy/attachments/20081008/ea06a2bb/attachment.pl
-------------- next part --------------
A non-text attachment was scrubbed...
Name: services_automount.patch.sig
Type: application/octet-stream
Size: 72 bytes
Desc: not available
Url : http://oss.tresys.com/pipermail/refpolicy/attachments/20081008/ea06a2bb/attachment.obj