[refpolicy] [PATCH] refpolicy: Add missing network related MLS constraints

Paul Moore paul.moore at hp.com
Mon Feb 23 11:37:51 CST 2009


On Friday 20 February 2009 08:37:30 pm Joe Nall wrote:
> How do processes talk to each other on local netlabel interfaces? lo
> for example is s0-s15:c1.c1023, any process above s0 would fail the
> test above communicating on localhost. I don't think that was the
> intent.

I suppose first things first: did you see the new patch posted on Friday 
(February 20th)?  It changed the constraints quite a bit based on feedback on 
the lists.  Please take a look at that patch and see if it looks okay to you, 
if not please yell loudly :)

-- 
paul moore
linux @ hp



More information about the refpolicy mailing list