Gentoo Archives: gentoo-hardened

From: Joshua Brindle <method@g.o>
To: "Robert M. Marmorstein" <rmmarm@×××××.EDU>
Cc: gentoo-hardened@l.g.o
Subject: Re: [gentoo-hardened] Portage System
Date: Tue, 27 Jul 2004 17:31:50
Message-Id: 41069174.9030000@gentoo.org
In Reply to: [gentoo-hardened] Portage System by "Robert M. Marmorstein"
1 There are a few ways to interpret what you are asking.
2 1) All files are labeled as they are moved to the filesystem. This is
3 done with the current system file_contexts file
4 2) if the daemon has a policy dependent on it (eg., apache-selinux) then
5 the policy will be installed to your policy dir (and backups are made)
6 but is not reloaded (and thus may have invalid contexts)
7 3) If you have FEATURES="loadpolicy" and there is a dependant policy
8 then it will be installed and reloaded to get the new contexts ready for
9 the application to install..
10
11 Hope that answers your question.
12
13 Joshua Brindle
14
15
16 Robert M. Marmorstein wrote:
17
18 > Does the portage system patch my selinux policy on the fly as I install
19 > new executables?
20 >
21 > Thanks!
22 >
23 > Robert Marmorstein
24 >
25 >
26 >
27 > --
28 > gentoo-hardened@g.o mailing list
29 >
30 >
31
32
33 --
34 gentoo-hardened@g.o mailing list