All of lore.kernel.org
 help / color / mirror / Atom feed
* I would like to change the behavior of MCS label creations in directory.
@ 2011-09-22 19:53 Daniel J Walsh
  2011-09-22 20:13 ` Guido Trentalancia
                   ` (2 more replies)
  0 siblings, 3 replies; 31+ messages in thread
From: Daniel J Walsh @ 2011-09-22 19:53 UTC (permalink / raw)
  To: SELinux

-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA1

Currently if I create a directory labeled

etc_t:s0:c1

And with a process running as unconfined_t:s0-s0:c0.c1023 create a
file within the directory, the file gets created with the label
etc_t:s0.   I would like to change the behavior to creating the file
as etc_t:s0:c1.

That way an administrator could modify files within a sandbox and have
the files be labeled correctly.

I believe this behavior differs from MLS but believe this would be
what the admin expects.

Is changing this a kernel or policy issue?
-----BEGIN PGP SIGNATURE-----
Version: GnuPG v1.4.11 (GNU/Linux)
Comment: Using GnuPG with Mozilla - http://enigmail.mozdev.org/

iEYEARECAAYFAk57kjMACgkQrlYvE4MpobO6GACgrZnzZl4OySYUkZATfl7RJPWb
z1YAn0m4wkHLWYWlR6urpuQ0tuGb+cdN
=uDm1
-----END PGP SIGNATURE-----

--
This message was distributed to subscribers of the selinux mailing list.
If you no longer wish to subscribe, send mail to majordomo@tycho.nsa.gov with
the words "unsubscribe selinux" without quotes as the message.

^ permalink raw reply	[flat|nested] 31+ messages in thread

end of thread, other threads:[~2011-11-22 19:42 UTC | newest]

Thread overview: 31+ messages (download: mbox.gz / follow: Atom feed)
-- links below jump to the message on this page --
2011-09-22 19:53 I would like to change the behavior of MCS label creations in directory Daniel J Walsh
2011-09-22 20:13 ` Guido Trentalancia
2011-09-22 20:31 ` Stephen Smalley
2011-09-22 20:32   ` Daniel J Walsh
2011-09-22 20:37     ` Stephen Smalley
2011-09-22 20:42       ` Stephen Smalley
2011-09-23 15:01         ` Daniel J Walsh
2011-09-23 15:07           ` Stephen Smalley
2011-09-23 16:06             ` Guido Trentalancia
2011-09-23 17:33               ` Daniel J Walsh
2011-09-24 22:05             ` David Windsor
2011-09-27 16:06               ` Stephen Smalley
2011-09-27 16:50                 ` David Windsor
2011-09-27 16:51                   ` Stephen Smalley
2011-09-27 18:13                 ` Daniel J Walsh
2011-10-14 15:57                   ` Daniel J Walsh
2011-10-18 12:34                     ` Christopher J. PeBenito
     [not found]                       ` <00243337-937e-4e6b-880b-ba2f351112e7@email.android.com>
2011-10-18 22:07                         ` David Windsor
2011-10-19 16:55                           ` Stephen Smalley
2011-10-19 15:31                       ` Joshua Brindle
2011-10-19 16:26                         ` Stephen Smalley
2011-11-22 18:59                           ` Eric Paris
2011-11-22 19:25                             ` Stephen Smalley
2011-11-22 19:37                               ` Eric Paris
2011-11-22 19:39                                 ` Stephen Smalley
2011-11-22 19:42                                   ` Eric Paris
2011-10-19 16:36                         ` Kyle Moffett
2011-10-19 17:41                         ` Daniel J Walsh
2011-10-19 17:47                           ` Joshua Brindle
2011-10-19 17:50                             ` Daniel J Walsh
2011-09-22 20:41 ` Guido Trentalancia

This is an external index of several public inboxes,
see mirroring instructions on how to clone and mirror
all data and code used by this external index.