On Jun 09, 2007, at 12:46:40, david@lang.hm wrote:Actually, it's easier than that. There are type attributes which may be assigned to an arbitrary set of types, and each "type" field in an access rule may use either a type or an attribute. So you don't actually need to modify existing rules when adding new types, you just add the appropriate existing attributes to your new type. For example, you could set up a "logfile" attribute which allows logrotate to archive old versions and allows audit-admin users to modify/delete them, then whenever you need to add a new logfile you just declare the "my_foo_log_t" type to have the "logfile" attribute. On the other hand, I seem to recall that typical "targeted" policies don't grant most of the additional access via access rules, they instead add a special case to the fundamental "constraints" in the policy (IE: If the subject type has the "trusted" attribute then skip some of the other type-based checks). Cheers, Kyle Moffett -
| Linus Torvalds | Linux 2.6.27-rc8 |
| Greg KH | [patch 00/71] 2.6.26-stable review |
| Dmitry Torokhov | 2.6.27-rc8+ - first impressions |
| Rafael J. Wysocki | [Bug #11215] INFO: possible recursive locking detected ps2 command |
git: | |
| Christian MICHON | Re: MinGW port - initial work uploaded |
| Luiz Fernando N. Capitulino | Libification project (SoC) |
| Linus Torvalds | People unaware of the importance of "git gc"? |
| Jakub Narebski | [RFC] Git User's Survey 2008 |
| Richard Stallman | Real men don't attack straw men |
| Tony Abernethy | Re: What is our ultimate goal?? |
| GVG GVG | ssh_exchange_identification: Connection closed by remote host |
| James Hartley | scp batch mode? |
| Ingo Molnar | Re: [TCP]: TCP_DEFER_ACCEPT causes leak sockets |
| Timo Teräs | Re: xfrm_state locking regression... |
| Ingo Molnar | Re: [bug] stuck localhost TCP connections, v2.6.26-rc3+ |
| Natalie Protasevich | [BUG] New Kernel Bugs |
