Re: [PATCH]: chcon: no longer abort on SELinux disabled kernel

2009-10-07 Thread Stephen Smalley
On Tue, 2009-10-06 at 10:14 +0200, Jim Meyering wrote: Jim Meyering wrote: Stephen Smalley wrote: ... Must have previously booted an ancient kernel with SELinux permissive and no policy loaded. Kernel was fixed by the commit below in 2006. I'd recommend that he run the following

Re: [PATCH]: chcon: no longer abort on SELinux disabled kernel

2009-10-07 Thread Stephen Smalley
On Wed, 2009-10-07 at 14:48 +0200, Jim Meyering wrote: Stephen Smalley wrote: ... FWIW, there is a subtle difference here: - chcon can in fact work on a SELinux-disabled kernel, as you can still set the security.* extended attributes as long as the filesystem provides handlers

Re: [PATCH]: chcon: no longer abort on SELinux disabled kernel

2009-10-07 Thread Stephen Smalley
On Wed, 2009-10-07 at 15:34 +0200, Jim Meyering wrote: Stephen Smalley wrote: On Wed, 2009-10-07 at 14:48 +0200, Jim Meyering wrote: Stephen Smalley wrote: ... FWIW, there is a subtle difference here: - chcon can in fact work on a SELinux-disabled kernel, as you can still set

Re: should GNU install call matchpathcon by default?

2008-05-21 Thread Stephen Smalley
with a simpler glob syntax (FCglob) that should help if it succeeds. -- Stephen Smalley National Security Agency ___ Bug-coreutils mailing list Bug-coreutils@gnu.org http://lists.gnu.org/mailman/listinfo/bug-coreutils

Re: should GNU install call matchpathcon by default?

2008-05-20 Thread Stephen Smalley
. That makes it slower than necessary and leaks memory. See the bug report for the discussion. Can we get this corrected in the upstream coreutils? Thanks. -- Stephen Smalley National Security Agency ___ Bug-coreutils mailing list Bug-coreutils