From dd31ddfd87e37acddf875a4aa5535ea8abcb49fb Mon Sep 17 00:00:00 2001 From: Stephen Smalley <sds@tycho.nsa.gov> Date: Fri, 27 Jul 2012 17:08:21 -0400 Subject: [PATCH] seinfo can be used to select types, and sebool is now supported. --- seapp_contexts | 5 +++-- 1 file changed, 3 insertions(+), 2 deletions(-) diff --git a/seapp_contexts b/seapp_contexts index 088937bf6..71eca75b8 100644 --- a/seapp_contexts +++ b/seapp_contexts @@ -3,11 +3,11 @@ # user (string) # seinfo (string) # name (string) +# sebool (string) # isSystemServer=true can only be used once. -# An unspecified boolean defaults to false. +# An unspecified isSystemServer defaults to false. # An unspecified string selector will match any value. # A user string selector that ends in * will perform a prefix match. -# seinfo= is only used when looking up app process security contexts. # All specified input selectors in an entry must match (i.e. logical AND). # Matching is case-insensitive. # Precedence rules: @@ -17,6 +17,7 @@ # (4) Longer user= prefix before shorter user= prefix. # (5) Specified seinfo= string before unspecified seinfo= string. # (6) Specified name= string before unspecified name= string. +# (7) Specified sebool= string before unspecified sebool= string. # # Outputs: # domain (string) -- GitLab