[Date Prev][Date Next] [Thread Prev][Thread Next] [Date Index] [Thread Index]

Re: dpkg and selinux



On Wed, Sep 01, 2004 at 02:30:03PM +0100, Scott James Remnant wrote:
> > the analogy is to imagine that chmod, chgrp and chown were a new
> > concept that had to be retrofitted onto a system where the default
> > permissions were noaccess, noaccess, 0000, with no members in the
> > group "noaccess".
> > 
> It's an interesting one, certainly I'd suggest the right solution would
> be to do such commands in postinst until such time as it was the default
> and the tar format could carry this information.  It would then become
> policy that it would be carried inside the tar file, just as chmod/
> chgrp/chown are carried today.

Historical note:

This is *exactly* what we used to do. Remember suidregister. The
scenario is identical and so are all the constraints. This postinst.d
stuff can't work for all the same reasons it couldn't work back then,
although I don't recall back far enough to know if anybody seriously
proposed it.

-- 
  .''`.  ** Debian GNU/Linux ** | Andrew Suffield
 : :' :  http://www.debian.org/ |
 `. `'                          |
   `-             -><-          |

Attachment: signature.asc
Description: Digital signature


Reply to: