4 ms·
Selinux will become useful when it precisely lists out what it disables with transparent explanations for assumptions made. And clear error messages or alerts w
by throw2016 9y ago
Selinux will become useful when it precisely lists out what it disables with transparent explanations for assumptions made. And clear error messages or alerts when it has just disabled something with proper logging.
Unlike with most open source software for things like selinux that disable a host of stuff by default, documentation cannot be an after thought. And why invent weird vague terminology, what is a context?
Things are complex as it is and people need to get things done. To have to waste man hours that could be used more productively more than once only to figure out its caused by selinux 'silently' without any proper error messages or logging and you do the sensible thing and disable it.
- Spivak 9y ago> what it disables with transparent explanations setroubleshoot > documentation cannot be an after thought Take a look at selinux-policy-doc, it's extensive. > what is a context It's a type. But 'type' as it refers to files means something else. It's just a label that describes what kind of file it is. user_home_dir_t is user files, httpd_sys_content_t is content that can be served by apache, nfsd_fs_t are files that that can be exported by NFS. > proper error messages or logging Every single denial is logged and it contains all the details why it was denied. You're asking for SELinux to log why it wasn't allowed which is done by setroubleshoot but isn't possible in general.
- emmelaich 9y ago> Every single denial is logged Not quite true. Some need to have debug turned on. See my other comment.