SELinux and third party installers

Mike Hearn mike at navi.cx
Mon Jan 3 16:08:21 UTC 2005


On Mon, 03 Jan 2005 10:31:13 -0500, Daniel J Walsh wrote:
> The file will get recieve the context of the parent directory.   Linker 
> is probably running in unconfined_t so it will not any problem. 

ldconfig doesn't though. Hmm.
 
> You should not have anything marked file_t unless they were created on a 
> machine that was not running
> SELinux.  This indicates that you need a relabel.

They're in my home directory. I did a "make relabel" when I enabled the
targetted policy. Is that not enough?

> Hopefully, good ideas usually get picked up by other distributions, of 
> course they might not think this is a good idea. :^)

Yeah this makes it rather hard for 3rd parties to track what's going on
here. Why can this stuff not all be done upstream and just merged with
Fedora at regular intervals?

>  Of course you could say that generally about differences between 
> distributions.

I could, and I do. It's a major pain for all concerned.

thanks -mike




More information about the fedora-selinux-list mailing list