[apt-rpm] apt and selinux (was: Re: restorecon vs. setfiles)

Stephen Smalley sds at epoch.ncsc.mil
Mon Jun 28 18:53:52 UTC 2004


On Mon, 2004-06-28 at 09:11, Panu Matilainen wrote:
> I wouldn't call it an apt-problem, you just need to put it into same 
> context as rpm. This should already be the case on Fedora Core 2, dunno 
> about upstream selinux policy packages - this is from stock FC2 
> /etc/security/selinux/src/policy/file_contexts/program/rpm.fc:
> /usr/bin/apt-get        --      system_u:object_r:rpm_exec_t
> /usr/bin/apt-shell      --      system_u:object_r:rpm_exec_t
> /usr/bin/synaptic   --          system_u:object_r:rpm_exec_t

It isn't just a policy issue; rpm had to be modified for SELinux to set
file security contexts when creating files.  Those changes are in the
upstream rpm, and yum seems to work as expected when updating.
  
-- 
Stephen Smalley <sds at epoch.ncsc.mil>
National Security Agency




More information about the fedora-selinux-list mailing list