devel's mcs breaks prelink and FC4 compat

Alexandre Oliva aoliva at redhat.com
Tue Oct 4 21:38:58 UTC 2005


On Oct  3, 2005, Stephen Smalley <sds at tycho.nsa.gov> wrote:

> - There is a patch pending against 2.6.15 that will enable SELinux to
> canonicalize getxattr results, so that it will return the :s0 always
> under MCS, even if the file hasn't been relabeled on disk.

Any chance it could also strip it out when writing to disk?  This
would improve on-disk compatibility with non-mcs, a point that I'd
planned to address in my previous e-mail, but forgot.  Currently, any
directories or files created while running FC devel become
inaccessible when I boot into FC4 on the same box, which is a little
bit annoying.

-- 
Alexandre Oliva         http://www.lsd.ic.unicamp.br/~oliva/
Red Hat Compiler Engineer   aoliva@{redhat.com, gcc.gnu.org}
Free Software Evangelist  oliva@{lsd.ic.unicamp.br, gnu.org}




More information about the fedora-selinux-list mailing list