Re: label folder in rootfs

2014-12-02 Thread Stephen Smalley
On 12/02/2014 02:49 AM, Inamdar Sharif wrote: This means that the exec outside /system will not be run by init. Is this a limitation?? But what if I want to run a service(executable) before /system is mounted and after SELinux initialization. So is it possible to do this way??

Re: wrote to log_device guidance

2014-12-02 Thread Stephen Smalley
On 12/02/2014 09:47 AM, William Roberts wrote: Well I am on an older version with no hopes of upgrading right now. I was wondering what happened to the references on that type. Ill look back at older policies. Just revert this change locally:

Re: wrote to log_device guidance

2014-12-02 Thread William Roberts
Thanks for the link Stephen On Tue, Dec 2, 2014 at 7:50 AM, Stephen Smalley s...@tycho.nsa.gov wrote: On 12/02/2014 09:47 AM, William Roberts wrote: Well I am on an older version with no hopes of upgrading right now. I was wondering what happened to the references on that type. Ill look

RE: label folder in rootfs

2014-12-02 Thread Inamdar Sharif
Yes , that I have tried and it works fine already. But here the problem doesnot seem as simple as we are thinking. Whatever we do its going to hit some or the other neverallow rule. For, ueventd, healthd, adbd, /sbin is labelled as rootfs which is why it works. But for /test it is labelled as