2010-06-02 20:15:33

by Daniel Walsh

[permalink] [raw]
Subject: [refpolicy] apps_userhelper.patch

http://people.fedoraproject.org/~dwalsh/SELinux/F14/apps_userhelper.patch

Add policy for consolehelper so staff_t can shutdown the machine


2010-07-08 14:58:47

by cpebenito

[permalink] [raw]
Subject: [refpolicy] apps_userhelper.patch

On 06/02/10 16:15, Daniel J Walsh wrote:
> http://people.fedoraproject.org/~dwalsh/SELinux/F14/apps_userhelper.patch
>
> Add policy for consolehelper so staff_t can shutdown the machine

Why does this need to be templated, rather than using a single
consolehelper_t?

--
Chris PeBenito
Tresys Technology, LLC
http://www.tresys.com | oss.tresys.com

2010-07-13 12:21:08

by Daniel Walsh

[permalink] [raw]
Subject: [refpolicy] apps_userhelper.patch

On 07/08/2010 10:58 AM, Christopher J. PeBenito wrote:
> On 06/02/10 16:15, Daniel J Walsh wrote:
>> http://people.fedoraproject.org/~dwalsh/SELinux/F14/apps_userhelper.patch
>>
>> Add policy for consolehelper so staff_t can shutdown the machine
>
> Why does this need to be templated, rather than using a single
> consolehelper_t?
>
Probably does not need it. I think I created this policy off of
userhelper, which was templated. The only think we might want would be
to allow

staff_t @consolehelper -> staff_consolehelper_t @ bin_t -> staff_t.

But I don't have a use case for this.

2010-07-19 17:48:42

by cpebenito

[permalink] [raw]
Subject: [refpolicy] apps_userhelper.patch

On 07/13/10 08:21, Daniel J Walsh wrote:
> On 07/08/2010 10:58 AM, Christopher J. PeBenito wrote:
>> On 06/02/10 16:15, Daniel J Walsh wrote:
>>> http://people.fedoraproject.org/~dwalsh/SELinux/F14/apps_userhelper.patch
>>>
>>> Add policy for consolehelper so staff_t can shutdown the machine
>>
>> Why does this need to be templated, rather than using a single
>> consolehelper_t?
>>
> Probably does not need it. I think I created this policy off of
> userhelper, which was templated. The only think we might want would be
> to allow
>
> staff_t @consolehelper -> staff_consolehelper_t @ bin_t -> staff_t.
>
> But I don't have a use case for this.

Ok, well then either we need to come up for a use case for the templated
form, otherwise I'd prefer to have a single domain.


--
Chris PeBenito
Tresys Technology, LLC
http://www.tresys.com | oss.tresys.com