Re: Resend: Sudo Changes for SELinux

[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]

 



-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA1

Todd Miller wrote:
> Daniel J Walsh wrote:
>> You are the boss.  Move it to /usr/libexec.  And I will fix policy to
>> label it correctly.  I would not put SELinux awareness into the
>> install, that is either "install", rpm. dpkg problem.
> 
> OK, I changed the path and updated the tarball.  Glad I don't have to
> worry about the label.
> 
>  - todd
There seems to be a bug. When I exit the shell it is not setting my tty
back.

In permissive mode.

$ ls -lZ `tty`
crw--w----  dwalsh tty staff_u:object_r:staff_devpts_t:s0 /dev/pts/2
 sudo sh
# ls -lZ `tty`
crw--w----  dwalsh tty staff_u:object_r:unconfined_devpts_t:s0 /dev/pts/2
# exit
$ ls -lZ `tty`
crw--w----  dwalsh tty staff_u:object_r:unconfined_devpts_t:s0 /dev/pts/2

In enforcing mode it kills the shell  :^(

I have it setup as staff_t and unconfined_t for root.


Other than this it looks greate.
-----BEGIN PGP SIGNATURE-----
Version: GnuPG v1.4.8 (GNU/Linux)
Comment: Using GnuPG with Fedora - http://enigmail.mozdev.org

iEYEARECAAYFAke7MkAACgkQrlYvE4MpobMX3ACfa/DoyI4J9NaJDsm93fX7ptZk
Ya4AnifwZsH8iLGjAhYF2n7Aaf+As0Xo
=NQhj
-----END PGP SIGNATURE-----

--
This message was distributed to subscribers of the selinux mailing list.
If you no longer wish to subscribe, send mail to majordomo@xxxxxxxxxxxxx with
the words "unsubscribe selinux" without quotes as the message.

[Index of Archives]     [Selinux Refpolicy]     [Linux SGX]     [Fedora Users]     [Fedora Desktop]     [Yosemite Photos]     [Yosemite Camping]     [Yosemite Campsites]     [KDE Users]     [Gnome Users]

  Powered by Linux