Gentoo Archives: gentoo-hardened

From: Sven Vermeulen <swift@g.o>
To: gentoo-hardened@l.g.o
Subject: Re: [gentoo-hardened] SELinux: portage_ro_role
Date: Sun, 18 Oct 2015 17:55:08
Message-Id: 20151018175503.GA785@gentoo.org
In Reply to: [gentoo-hardened] SELinux: portage_ro_role by Luis Ressel
1 On Thu, Oct 15, 2015 at 12:02:41PM +0200, Luis Ressel wrote:
2 > our portage policy includes a portage_ro_role interface to allow
3 > read-only access to portage data. As usual with _role interfaces,
4 > according to the documentation the interface takes a role as the first
5 > ($1) and a type as the second argument ($2). However, the directives
6 > in the interface actually expect $1 to be a type.
7 >
8 > So, we should either
9 > 1) replace $1 with $2 inside the interface, or
10 > 2) rename the interface to something without _role and fix the
11 > documentation.
12
13 My suggestion is to go with 1 - fix the use of the $1 and $2 parameters.
14
15 Wkr,
16 Sven Vermeulen