• 1
It would support MCS as is. You would need to modify the MLS Policy package to support a minimal policy install, and then it would probably work. Not sure what additional policy modules would be required.

In MLS Policy you don't have unconfined(initrc_t) so it would be more difficult.

Are you sure that MLS don't have unconfined(initrc_t) ?

I see:

config/appconfig-mls/unconfined_u_default_contexts:2:system_r:initrc_t:s0 unconfined_r:unconfined_t:s0
config/appconfig-mls/xguest_u_default_contexts:2:system_r:initrc_su_t:s0 xguest_r:xguest_t:s0

Well unconfined_u being in the mls appconfig is a bug.

initrc_t does exist, but it is not wrapped in the unconfined_domain() attribute.

seinfo -xunconfined_domain_type

On an MLS policy should return no domains.

How can I modify refpolicy to add to MLS support unconfined_domain_type ?
Could you help me please?

Contact me via email or on irc #selinux on freenode. This is a little difficult to do on a blog.

What is your nickname on irc #selinux ?

IRC: dwalsh
Email: dwalsh@redhat.com
Titter: #rhatdan

  • 1

Log in