From: dwalsh@redhat.com (Daniel J Walsh) Date: Thu, 06 Feb 2014 12:19:29 +0100 Subject: [refpolicy] I would like to suggest that we remove the tmpfs_t and type alias them to tmp_t. Message-ID: <52F36FC1.4020001@redhat.com> To: refpolicy@oss.tresys.com List-Id: refpolicy.oss.tresys.com -----BEGIN PGP SIGNED MESSAGE----- Hash: SHA1 - From a security point of view, treating this differently has little value in my mind. I believe policy writers just write both rules in place. I guess you could argue that combining them together would allow a domain to write to /dev/shm /tmp and /var/tmp and currently you could only write to one. What do people think about this? -----BEGIN PGP SIGNATURE----- Version: GnuPG v1 Comment: Using GnuPG with Thunderbird - http://www.enigmail.net/ iEYEARECAAYFAlLzb8EACgkQrlYvE4MpobPhFwCg1IIHpepYnmNWIDXbmgKIk2sn O4kAn2yMkxBzZ46bZ89nSffZvFDzhP7a =aNMc -----END PGP SIGNATURE-----