SELinux macro broken?

Christoph Höger choeger at cs.tu-berlin.de
Wed Dec 26 17:09:29 UTC 2007


Hi,

when I tried to build a custom SELinux module, this strange behavior
occured:

when I used:

libs_read_lib_files(tomcat5_t)

I got "read" denied source: tomcat5_t target: lib_t

but using

require {
        type lib_t;
        type tomcat5_t;
        class file read;
}

allow tomcat5_t lib_t:file read;

worked fine. Although this should essentially be the same in my
understanding.

Any explanations for that?

regards

christoph




More information about the fedora-devel-list mailing list