2009-11-12 21:07:33

by Daniel Walsh

[permalink] [raw]
Subject: [refpolicy] roles_staff.patch

http://people.fedoraproject.org/~dwalsh/SELinux/F12/roles_staff.patch

add setexec so staff_t can run sandbox. Maybe want to add to user_t also.

I think we need to remove all the role transition stuff from staff_t and allow users to choose which domains they want to play with


2010-02-17 14:05:32

by cpebenito

[permalink] [raw]
Subject: [refpolicy] roles_staff.patch

On Thu, 2009-11-12 at 16:07 -0500, Daniel J Walsh wrote:
> http://people.fedoraproject.org/~dwalsh/SELinux/F12/roles_staff.patch
>
> add setexec so staff_t can run sandbox. Maybe want to add to user_t
> also.
>
> I think we need to remove all the role transition stuff from staff_t
> and allow users to choose which domains they want to play with

Same thing as for unprivuser.

--
Chris PeBenito
Tresys Technology, LLC
(410) 290-1411 x150