From: cpebenito@tresys.com (Christopher J. PeBenito) Date: Wed, 29 Aug 2012 08:52:37 -0400 Subject: [refpolicy] [PATCH v4 0/4] Support /run/* creation for initrc_t In-Reply-To: <20120825182417.GA23427@siphos.be> References: <20120825182417.GA23427@siphos.be> Message-ID: <503E1095.9090307@tresys.com> To: refpolicy@oss.tresys.com List-Id: refpolicy.oss.tresys.com On 08/25/12 14:24, Sven Vermeulen wrote: > Due to the introduction of /run, many init scripts need to create the daemon run > dirs (such as /run/udev for the udev init script). To simplify this, we > introduce the "daemonrundir" attribute to which initrc_t has the necessary > create_dirs_perms granted. > > Changes since v3 > ---------------- > > - Add in setattr rights towards the daemonrundir types for initrc_t > - Add in a couple of more identified domains that need this > - Remove deprecation of previous functions, they are not used anymore, but not > deprecated. The referred alternative (init_daemon_run_dir) is only when the > methods were called for initrc_t. This set merged. It think one minor additional tweak would have init_daemon_run_dir() to call files_pid_file() since the former is a subset of the latter. -- Chris PeBenito Tresys Technology, LLC www.tresys.com | oss.tresys.com