From: russell@coker.com.au (Russell Coker) Date: Tue, 4 Apr 2017 18:02:15 +1000 Subject: [refpolicy] [PATCH] misc fc changes In-Reply-To: <20170404075356.GD10685@t450.enp8s0.d30> References: <20170402085805.2zlddx2evzcgxgop@athena.coker.com.au> <201704041749.35398.russell@coker.com.au> <20170404075356.GD10685@t450.enp8s0.d30> Message-ID: <201704041802.15604.russell@coker.com.au> To: refpolicy@oss.tresys.com List-Id: refpolicy.oss.tresys.com On Tue, 4 Apr 2017 05:53:56 PM Dominick Grift via refpolicy wrote: > > If at some future time we have something like a /etc/network/if-up-d > > directory then we probably want the same context for the files it > > contains. > > As for escaping the periods: i mean this (for example): > > /etc/network/if-pre-up\.d/.* -- gen_context(system_u:object_r:initrc_ex > ec_t,s0) > > if you do not escape the period then the period might be misinterpreted > later on I know what you mean. But my definition of "misinterpreted" doesn't match yours. I think that all ip-up*d directories should have the same context if they happen to exist. -- My Main Blog http://etbe.coker.com.au/ My Documents Blog http://doc.coker.com.au/