Re: [systemd-devel] SELinux type transition rule not working

2017-03-03 Thread Ian Pilcher
On 03/03/2017 02:19 PM, Simon Sekidde wrote: Thanks. Lets try to get a template going and we can help clean it up. I've been scrambling to get my home network setup (after migrating the main network server/router from CentOS 6 -> 7), so it's not surprise if things are a bit hacky right now.

Re: [systemd-devel] Can a systemd --user instance rely on After= of systemd --system instance?

2017-03-03 Thread Kai Krakow
Am Sun, 26 Feb 2017 21:35:27 +0100 schrieb Lennart Poettering : > On Sat, 25.02.17 17:34, Patrick Schleizer > (patrick-mailingli...@whonix.org) wrote: > > > Hi, > > > > I read, that a systemd --user instance cannot use Requires=. > > > > But what about After=? Can a

Re: [systemd-devel] SELinux type transition rule not working

2017-03-03 Thread Simon Sekidde
- Original Message - > From: "Ian Pilcher" > To: "Simon Sekidde" > Cc: "Systemd" , seli...@tycho.nsa.gov > Sent: Friday, March 3, 2017 2:32:54 PM > Subject: Re: [systemd-devel] SELinux type transition rule

Re: [systemd-devel] SELinux type transition rule not working

2017-03-03 Thread Ian Pilcher
On 03/03/2017 10:45 AM, Simon Sekidde wrote: Ian do you have a copy of this custom policy somewhere? https://github.com/ipilcher/squoxy/blob/master/squoxy.te -- Ian Pilcher

Re: [systemd-devel] SELinux type transition rule not working

2017-03-03 Thread Simon Sekidde
Ian do you have a copy of this custom policy somewhere? - Original Message - > From: "Simon Sekidde" > To: "Ian Pilcher" > Cc: "Systemd" , lenn...@poettering.net, > seli...@tycho.nsa.gov > Sent: Friday,

Re: [systemd-devel] SELinux type transition rule not working

2017-03-03 Thread Stephen Smalley
On Fri, 2017-03-03 at 09:36 -0600, Ian Pilcher wrote: > On 03/02/2017 12:12 AM, Jason Zaman wrote: > > > > On Wed, Mar 01, 2017 at 05:51:01PM -0600, Ian Pilcher wrote: > > > > > > On 03/01/2017 05:28 PM, Ian Pilcher wrote: > > > > > > > > Per Lennart's response, systemd *should* be honoring the

Re: [systemd-devel] SELinux type transition rule not working

2017-03-03 Thread Simon Sekidde
- Original Message - > From: "Ian Pilcher" > To: "Simon Sekidde" > Cc: "Systemd" , seli...@tycho.nsa.gov, > lenn...@poettering.net > Sent: Friday, March 3, 2017 10:44:18 AM > Subject: Re: [systemd-devel]

Re: [systemd-devel] SELinux type transition rule not working

2017-03-03 Thread Ian Pilcher
On 03/02/2017 09:13 AM, Simon Sekidde wrote: I assume this would be a pid file? You assume correctly. If so then what you are probably looking for is a filename_trans rule and will require a new interface in squid.if for this. Try something like interface(`squid_filetrans_named_content',`

Re: [systemd-devel] SELinux type transition rule not working

2017-03-03 Thread Ian Pilcher
On 03/02/2017 12:12 AM, Jason Zaman wrote: On Wed, Mar 01, 2017 at 05:51:01PM -0600, Ian Pilcher wrote: On 03/01/2017 05:28 PM, Ian Pilcher wrote: Per Lennart's response, systemd *should* be honoring the file context rules when creating the directory. It's almost as if the directory is being

Re: [systemd-devel] How to use machinectl to get a running centos container?

2017-03-03 Thread Lennart Poettering
On Sat, 04.03.17 01:38, Daurnimator (q...@daurnimator.com) wrote: > On 3 March 2017 at 20:58, Lennart Poettering wrote: > > On Fri, 03.03.17 12:34, Daurnimator (q...@daurnimator.com) wrote: > > > >> I'm trying to set up a centos 7 container with machinectl. > >> I've tried

Re: [systemd-devel] How to use machinectl to get a running centos container?

2017-03-03 Thread Daurnimator
On 3 March 2017 at 20:58, Lennart Poettering wrote: > On Fri, 03.03.17 12:34, Daurnimator (q...@daurnimator.com) wrote: > >> I'm trying to set up a centos 7 container with machinectl. >> I've tried to run: >> >> machinectl pull-raw --verify=no >>

Re: [systemd-devel] How to use machinectl to get a running centos container?

2017-03-03 Thread Lennart Poettering
On Fri, 03.03.17 12:34, Daurnimator (q...@daurnimator.com) wrote: > I'm trying to set up a centos 7 container with machinectl. > I've tried to run: > > machinectl pull-raw --verify=no > http://cloud.centos.org/centos/7/images/CentOS-7-x86_64-GenericCloud-1701.raw.tar.gz Hmm, what is a