2009-03-24 14:09:53

by Daniel Walsh

[permalink] [raw]
Subject: [refpolicy] system_lvm.patch

http://people.fedoraproject.org/~dwalsh/SELinux/F11/system_lvm.patch

Additional lvm file context

clvmd needs additional capabilities

needs to setsched

clvmd_t will create device, has SELinux awareness to label them correctly

lvm uses dbus

In targeted policy we are running lvm and clvmd unconfined

lvm can load kernel modules


2009-05-06 14:58:03

by cpebenito

[permalink] [raw]
Subject: [refpolicy] system_lvm.patch

On Tue, 2009-03-24 at 10:09 -0400, Daniel J Walsh wrote:
> http://people.fedoraproject.org/~dwalsh/SELinux/F11/system_lvm.patch
>
> Additional lvm file context
>
> clvmd needs additional capabilities
>
> needs to setsched
>
> clvmd_t will create device, has SELinux awareness to label them
> correctly
>
> lvm uses dbus
>
> In targeted policy we are running lvm and clvmd unconfined
>
> lvm can load kernel modules

Merged with some rearranging.

--
Chris PeBenito
Tresys Technology, LLC
(410) 290-1411 x150