fedora-selinux January 2012 archive
Main Archive Page > Month Archives  > fedora-selinux archives
fedora-selinux: Defining new access vectors & security class

Defining new access vectors & security classes in policy modules ?

From: Daniel P. Berrange <berrange_at_nospam>
Date: Fri Jan 20 2012 - 12:46:07 GMT
To: selinux@lists.fedoraproject.org

I'm working on adding fine grained access control to libvirt and need to
define a bunch of new object classes & their corresponding access
vectors.

For the sake of simplifying my developement / testing cycle, I'm wondering
if it is possible to define access vectors / security classes in the
individual policy module files, rather than in the top level global
flash/{access_vectors,security_classes} file, which would require me to
rebuild the entire policy for every change I make.

Regards,
Daniel
-- |: http://berrange.com -o- http://www.flickr.com/photos/dberrange/ :| |: http://libvirt.org -o- http://virt-manager.org :| |: http://autobuild.org -o- http://search.cpan.org/~danberr/ :| |: http://entangle-photo.org -o- http://live.gnome.org/gtk-vnc :| -- selinux mailing list selinux@lists.fedoraproject.org https://admin.fedoraproject.org/mailman/listinfo/selinux