Re: [systemd-devel] SELinux labels on unix sockets

2015-03-25 Thread Dominick Grift
, and the setfscreatecon() stuff should *probably* go. -- 02DFF788 4D30 903A 1CF3 B756 FB48 1514 3148 83A2 02DF F788 http://keys.gnupg.net/pks/lookup?op=vindexsearch=0x314883A202DFF788 Dominick Grift pgpuyk4nWBLag.pgp Description: PGP signature ___ systemd-devel mailing

Re: [systemd-devel] SELinux labels on unix sockets

2015-03-25 Thread Dominick Grift
On Wed, Mar 25, 2015 at 10:31:41PM +0100, Dominick Grift wrote: For the sock *file*, i would argue, that indeed the setfscreatecon is not strictly needed, and that the labeling for this can be taken care of by using type transition rules in the security policy as suggested. However

Re: [systemd-devel] systemd-nspawn trouble

2015-04-22 Thread Dominick Grift
1CF3 B756 FB48 1514 3148 83A2 02DF F788 http://keys.gnupg.net/pks/lookup?op=vindexsearch=0x314883A202DFF788 Dominick Grift pgpbPvtZbgCoo.pgp Description: PGP signature ___ systemd-devel mailing list systemd-devel@lists.freedesktop.org http

Re: [systemd-devel] systemd-nspawn trouble

2015-04-22 Thread Dominick Grift
/pks/lookup?op=vindexsearch=0x314883A202DFF788 Dominick Grift pgpNEepiniQub.pgp Description: PGP signature ___ systemd-devel mailing list systemd-devel@lists.freedesktop.org http://lists.freedesktop.org/mailman/listinfo/systemd-devel

[systemd-devel] [PATCH] selinux: fix missing SELinux unit access check

2015-06-09 Thread Dominick Grift
Development has moved to github.com/systemd It is probably better to submit a Github Push Request there if you have not done so already. Thanks -- 02DFF788 4D30 903A 1CF3 B756 FB48 1514 3148 83A2 02DF F788 http://keys.gnupg.net/pks/lookup?op=vindexsearch=0x314883A202DFF788 Dominick Grift

Re: [systemd-devel] [HEADSUP] systemd-222 around the corner

2015-07-07 Thread Dominick Grift
83A2 02DF F788 http://keys.gnupg.net/pks/lookup?op=vindexsearch=0x314883A202DFF788 Dominick Grift pgpFIFO8nUgqE.pgp Description: PGP signature ___ systemd-devel mailing list systemd-devel@lists.freedesktop.org http://lists.freedesktop.org/mailman

Re: [systemd-devel] grant users access to certain services only

2015-08-21 Thread Dominick Grift
On Fri, Aug 21, 2015 at 08:25:56PM +1000, Daurnimator wrote: On 21 August 2015 at 19:57, Dominick Grift dac.overr...@gmail.com wrote: i think it kind of sucks that systemctl --user list-units can be used to determine who is currently logged in. You can see with `loginctl list-users` too

Re: [systemd-devel] grant users access to certain services only

2015-08-21 Thread Dominick Grift
=0x314883A202DFF788 Dominick Grift pgpNZmfN8MOtq.pgp Description: PGP signature ___ systemd-devel mailing list systemd-devel@lists.freedesktop.org http://lists.freedesktop.org/mailman/listinfo/systemd-devel

Re: [systemd-devel] grant users access to certain services only

2015-08-21 Thread Dominick Grift
/lookup?op=vindexsearch=0x314883A202DFF788 Dominick Grift pgplvuCg2ZlLW.pgp Description: PGP signature ___ systemd-devel mailing list systemd-devel@lists.freedesktop.org http://lists.freedesktop.org/mailman/listinfo/systemd-devel

Re: [systemd-devel] grant users access to certain services only

2015-08-21 Thread Dominick Grift
83A2 02DF F788 http://keys.gnupg.net/pks/lookup?op=vindexsearch=0x314883A202DFF788 Dominick Grift ___ systemd-devel mailing list systemd-devel@lists.freedesktop.org http://lists.freedesktop.org/mailman/listinfo/systemd-devel

Re: [systemd-devel] grant users access to certain services only

2015-08-21 Thread Dominick Grift
stop status }; -- 02DFF788 4D30 903A 1CF3 B756 FB48 1514 3148 83A2 02DF F788 http://keys.gnupg.net/pks/lookup?op=vindexsearch=0x314883A202DFF788 Dominick Grift ___ systemd-devel mailing list systemd-devel@lists.freedesktop.org http

Re: [systemd-devel] [HEADSUP] systemd-222 around the corner

2015-07-07 Thread Dominick Grift
On Tue, Jul 07, 2015 at 09:56:45AM +0100, Richard Maw wrote: On Tue, Jul 07, 2015 at 09:25:21AM +0300, Andrei Borzenkov wrote: On Tue, Jul 7, 2015 at 9:02 AM, Dominick Grift dac.overr...@gmail.com wrote: Would be nice if anyone could at least confirm or deny this issue that I've

Re: [systemd-devel] [systemd SELinux] system status permission

2019-10-07 Thread Dominick Grift
== > Ian Pilcher arequip...@gmail.com > "I grew up before Mark Zuckerberg invented friendship" > ==== -- Key

Re: [systemd-devel] [systemd SELinux] system status permission

2019-10-07 Thread Dominick Grift
On Mon, Oct 07, 2019 at 06:51:57PM +0200, Dominick Grift wrote: > On Mon, Oct 07, 2019 at 11:03:44AM -0500, Ian Pilcher wrote: > > I am hitting this (non-fatal) denial when reloading a service via the > > systemd dbus API: > > > > > type=USER_AVC msg=audit(15

[systemd-devel] systemd-pcrlock Failed to submit super PCR policy

2024-02-05 Thread Dominick Grift
mbus systemd-pcrlock[35974]: Ignoring device path element type=0x01 subtype=0x01 Feb 04 20:00:01 nimbus systemd-pcrlock[35974]: Ignoring device path element type=0x02 subtype=0x01 Feb 04 20:00:01 nimbus systemd-pcrlock[35974]: TPM PC Client Platform Firmware Profile: family 2.0, revision 0.0 Feb 0

Re: [systemd-devel] /etc/machine-id has wrong SELinux file context and changes on second boot

2024-03-18 Thread Dominick Grift
t; Do you have an idea how to work around this problem? > > Best, > Holger -- gpg --locate-keys dominick.gr...@defensec.nl (wkd) Key fingerprint = FCD2 3660 5D6B 9D27 7FC6 E0FF DA7E 521F 10F6 4098 Dominick Grift Mastodon: @kcini...@defensec.nl