What kind of scripts legitimately need to tamper with other packages'
files? Examples?
I take you you mean non config file examples
Right now I see things like this in the current policy for rpm_script_t
(on strict, no less...):
Not sure why all of those things are necessary...
# ideally we would not need this
auth_manage_all_files_except_shadow(rpm_script_t)
# ideally we would not need this
dev_manage_generic_blk_files(rpm_script_t)
dev_manage_generic_chr_files(rpm_script_t)
dev_manage_all_blk_files(rpm_script_t)
dev_manage_all_chr_files(rpm_script_t)
storage_raw_read_fixed_disk(rpm_script_t)
storage_raw_write_fixed_disk(rpm_script_t)
--
fedora-devel-list mailing list
fedora-devel-list@xxxxxxxxxx
https://www.redhat.com/mailman/listinfo/fedora-devel-list