Re: [yocto] [meta-selinux][PATCH 0/2] initscripts/devpts.sh: fix context for /dev/pts

2014-06-23 Thread Pascal Ouyang
于 14-5-12 下午3:31, wenzong@windriver.com 写道: From: Wenzong Fan wenzong@windriver.com devpts use file_use_trans to allocate security contexts. As there are no range_trans rules for initrc_t mounting devpts, the security level of mountpoint will be derived from the initrc process, to be

[yocto] [meta-selinux][PATCH 0/2] initscripts/devpts.sh: fix context for /dev/pts

2014-05-12 Thread wenzong.fan
From: Wenzong Fan wenzong@windriver.com devpts use file_use_trans to allocate security contexts. As there are no range_trans rules for initrc_t mounting devpts, the security level of mountpoint will be derived from the initrc process, to be systemhigh (s15:c0.c1023), instead of expected