git/list[1] front-page[2] threads[3] people[4] search[5] about
 

Re: SeLinux integration

From
DQDavid P. Quigley <dpquigl@tycho.nsa.gov>
Date
Aug 18, 2008, 14:29 UTC
Message-ID
<1219069787.2609.86.camel@moss-terrapins.epoch.ncsc.mil>
In-Reply-To
<6341D084-1A83-4C0F-8C45-943916612D48@gmx.de>
On Sun, 2008-08-17 at 12:44 +0200, Jens Neuhalfen wrote:
Show 33 quoted lines
> Hi,
> 
> I  wrote an SeLinux policy and an init.d script  for the git-daemon  
> and now seek for comments and improvements.
> 
> The scripts were tested on my Centos 5.2 box  and an older version had  
> been tested on FC 9.
> 
>   Features:
>     * multiple configuration files for the init.d script
>     * selinux support for git daemon
>     * seboolean (git_daemon_update_repository) that forces git-daemon  
> into strict read-only mode when set to false
> 
> TODO
>   * The policy and the accompanying init.d script still lack  
> documentation
>   * see selinux/BUGS and initd/BUGS
> 
> Feel free to pull from my repository and comment. If the everything is  
> 'good' I will send patches to the list, so that SeLinux support can be  
> integrated into the main repository.
> 
> 
>   git://www.neuhalfen.name/git-selinux.git
> 
> 
> Jens
> 
> --
> To unsubscribe from this list: send the line "unsubscribe git" in
> the body of a message to majordomo@vger.kernel.org
> More majordomo info at  http://vger.kernel.org/majordomo-info.html
Hello,
   It is great to see people other than the core policy developers
working on SELinux policy. One thing I would suggest is to post your
policy to the new reference policy mailing list for SELinux. This way
people such as Chris PeBenito and Dan Walsh can look over it and give
suggestions as well. You can find the list at the link below [1]. 
[1]http://oss.tresys.com/mailman/listinfo/refpolicy
Dave
Previous: Petr Baudis
Message 7 of 7 in “SeLinux integration”
  1. Jens NeuhalfenAug 17, 2008
  2. Christian JaegerAug 18, 2008
  3. Jens NeuhalfenAug 18, 2008
  4. Christian JaegerAug 18, 2008
  5. Björn SteinbrinkAug 18, 2008
  6. Petr BaudisAug 18, 2008
  7. David P. QuigleyAug 18, 2008

Read the whole thread, see it on lore, or plain text.

$ cat FOOTERMessages come from the public archive at lore.kernel.org/git, fetched every hour. The front page is chosen and written each morning by an AI editor and can be wrong; the threads themselves are the record. About and API. For agents: an MCP server at https://gitlist.dev/mcp, and any thread, story or person page as Markdown by adding .md to its URL (or sending Accept: text/markdown). Details in /llms.txt.