How to get an SELinux policy change

Paul Howarth paul at city-fan.org
Fri Nov 7 14:17:25 UTC 2008


On Fri, 7 Nov 2008 07:10:08 -0700
"Jerry James" <loganjerry at gmail.com> wrote:

> 2008/11/7 yersinia <yersinia.spiros at gmail.com>:
> > Do look useful this docu ?
> >
> > http://fedoraproject.org/wiki/PackagingDrafts/SELinux/PolicyModules
> 
> Thank you.  That is a very useful document.  However, it does not
> appear to answer my question.  I need a non-default security context
> for binaries that are both built and executed in the %build script,
> when the policy module has not yet been installed.  It appears to me
> that there are only two ways to accomplish this: keep abusing
> java_exec_t like I have been, or get a GCL policy incorporated into
> selinux-policy* prior to building GCL.  Am I wrong?  Is there some
> other option?  Does anyone have any guidance to offer me on which
> option to pursue?  Thanks,

Move the discussion to fedora-selinux-list where it'll get Dan's
attention more quickly and probably result in a GCL policy being
incorporated into the main selinux-policy package.

Paul.




More information about the fedora-devel-list mailing list