2011-03-03 10:43:10

by mgrepl

[permalink] [raw]
Subject: [refpolicy] [patch 1/2] namespace: new policy for namespace.init script

http://mgrepl.fedorapeople.org/F15/apps_namespace_p1.patch

* namespace_init policy for /etc/security/namespace.init script to
make polyinstantiation working

Description:

When a normal user logs on for the first time with using
polyinstantiation,
files .bash* are copied to the home dir which caused
permission errors.


2011-03-21 14:42:02

by cpebenito

[permalink] [raw]
Subject: [refpolicy] [patch 1/2] namespace: new policy for namespace.init script

On 03/03/11 05:43, Miroslav Grepl wrote:
> http://mgrepl.fedorapeople.org/F15/apps_namespace_p1.patch
>
> * namespace_init policy for /etc/security/namespace.init script to
> make polyinstantiation working
>
> Description:
>
> When a normal user logs on for the first time with using
> polyinstantiation,
> files .bash* are copied to the home dir which caused
> permission errors.

* I'd like to move this to the admin layer.
* I'd like to trim the name to namespace_t
* userdom_relabelto_user_home_files() is missing.

--
Chris PeBenito
Tresys Technology, LLC
http://www.tresys.com | oss.tresys.com