Re: [PATCH 1/1] [bug556972-srivasta]: Explicitly allow /selinux and /sys as FHS exceptions

2009-11-21 Thread Manoj Srivastava
On Sat, Nov 21 2009, Kees Cook wrote: > Hi, > > On Fri, Nov 20, 2009 at 12:33:50PM -0600, Manoj Srivastava wrote: >> The report #556972 was filed about a FHS violation in mounting >> selinuxfs on /selinux, which is accurate. Additionally, /sys does not >> appear in the FHS either, and is

Re: [PATCH 1/1] Use the "Failed-Config" state instead of the synonymous halfconfigured

2009-11-21 Thread Guillem Jover
Hi! On Sat, 2009-11-21 at 00:38:12 -0600, Manoj Srivastava wrote: > These terms are synonyms. dpkg and dselect use halfconfigured > internally and Failed-config when talking to the user. This patch > ensures that policy uses the same term as dpkg does when talking to > the user ("Failed-Config") f

Re: [PATCH 1/1] [bug556972-srivasta]: Explicitly allow /selinux and /sys as FHS exceptions

2009-11-21 Thread Kees Cook
Hi, On Fri, Nov 20, 2009 at 12:33:50PM -0600, Manoj Srivastava wrote: > The report #556972 was filed about a FHS violation in mounting > selinuxfs on /selinux, which is accurate. Additionally, /sys does not > appear in the FHS either, and is thus in a similar situation. > > Now,