On Tue, Sep 11, 2012 at 5:28 PM, Stephen Smalley <sds@xxxxxxxxxxxxx> wrote: > I would tend to view the collection hooks as just part of the overall > hook interface for plugins. You are defining per-transaction, > per-package, and per-file hooks, and per-collection hooks are just > another case to consider (unless I misunderstand). Yes, I think they are certainly making sense as hooks, but the problem is that the plug-in interface currently defined as "collection plug-in". It would be strange to add some per-file hooks to smth that is defined as "collection plug-in". Maybe we can rename the whole construction and reorganize it in a more generic way? I will ask rpm maintainer about this. > If not, I don't see why it cannot be made to support that functionality. > It isn't truly unique to security; other kinds of functional plugins may > need/want to be able to abort the installation. Agree, I guess if we go the path of defining the general rpm plugin interface, then this can be included there too. Best Regards, Elena. -- This message was distributed to subscribers of the selinux mailing list. If you no longer wish to subscribe, send mail to majordomo@xxxxxxxxxxxxx with the words "unsubscribe selinux" without quotes as the message.