2009-11-12 22:18:09

by Daniel Walsh

[permalink] [raw]
Subject: [refpolicy] system_userdomain.patch

http://people.fedoraproject.org/~dwalsh/SELinux/F12/system_userdomain.patch

Widely varied from upstream because of consolodating on attributes rather then types.


2010-02-12 20:26:16

by cpebenito

[permalink] [raw]
Subject: [refpolicy] system_userdomain.patch

On Thu, 2009-11-12 at 17:18 -0500, Daniel J Walsh wrote:
> http://people.fedoraproject.org/~dwalsh/SELinux/F12/system_userdomain.patch
>
> Widely varied from upstream because of consolodating on attributes
> rather then types.

In principle this is fine, but I'm trying to hold out for a proper
clone/copy mechanism to be available again. When that comes around, I'd
have to undo this change.

--
Chris PeBenito
Tresys Technology, LLC
(410) 290-1411 x150

2010-02-13 12:20:49

by Daniel Walsh

[permalink] [raw]
Subject: [refpolicy] system_userdomain.patch

On 02/12/2010 03:26 PM, Christopher J. PeBenito wrote:
> On Thu, 2009-11-12 at 17:18 -0500, Daniel J Walsh wrote:
>> http://people.fedoraproject.org/~dwalsh/SELinux/F12/system_userdomain.patch
>>
>> Widely varied from upstream because of consolodating on attributes
>> rather then types.
>
> In principle this is fine, but I'm trying to hold out for a proper
> clone/copy mechanism to be available again. When that comes around, I'd
> have to undo this change.
>
Maybe, but we have been waiting for the clone/copy mechansim for several years now. :^(

I have a hard time many people can use confined users without this mechanism or other distros do not use the exec* checks.
Or they do not use java/mono applications.