reopen 526133
thanks

> > I have a machine where the unconfined policy is loaded but not used,
> > so my only way in is staff_u with staff_r and transition to sysadm_r:
>         Hmm. This is not the default, so the bug in the policy package
>  is not grave.

Please explain how a transition from a setup with unconfined and
unconfined_u users to staff_u and sysadm_u should work if not the
following way:
- Change user.
- Remove unconfined policy.

>         And not only is the change nothe default, it is weird: Either
>  you use targeted policy, which means you load and use unconfined policy
>  module, or you unload the unconfined module to make it strict. The
>  hybrid approach is .. unusual.

No, it is not. All policy modules are shipped by this package. So you
must document conflicts at least.

Bastian



-- 
To UNSUBSCRIBE, email to debian-bugs-rc-requ...@lists.debian.org
with a subject of "unsubscribe". Trouble? Contact listmas...@lists.debian.org

Reply via email to