67 lines
2.7 KiB
Diff
67 lines
2.7 KiB
Diff
From eb250ffcf89287560ce1b1cda94ca429828ce645 Mon Sep 17 00:00:00 2001
|
|
From: Pranav Lawate <pran.lawate@gmail.com>
|
|
Date: Tue, 7 Oct 2025 20:36:13 +0530
|
|
Subject: [PATCH] improve semanage man pages: Add examples for -r RANGE flag
|
|
usage
|
|
Content-type: text/plain
|
|
|
|
This patch adds missing examples to the semanage-port and
|
|
semanage-fcontext man pages showing the correct usage of the -r RANGE
|
|
flag for MLS/MCS systems. Currently, users who try to use the -r flag
|
|
without proper examples often encounter unclear error messages when
|
|
they provide invalid range formats.
|
|
|
|
For example, here is a command with wrong range string value:
|
|
libsepol.mls_from_string: invalid MLS context s0.c0 (No such file or directory)
|
|
[...error output...]
|
|
|
|
The added examples demonstrate:
|
|
- Correct MLS range format: s0:c0.c255
|
|
- Complete command syntax with the -r flag for both port and
|
|
fcontext operations
|
|
- Clear indication that this is for MLS/MCS systems only
|
|
- Verification method using seinfo for port changes (semanage port -l
|
|
only shows type, not MLS range)
|
|
- Use -F flag to restorecon in fcontext example (required to force
|
|
relabeling)
|
|
|
|
Signed-off-by: Pranav Lawate <pran.lawate@gmail.com>
|
|
Acked-by: Stephen Smalley <stephen.smalley.work@gmail.com>
|
|
---
|
|
python/semanage/semanage-fcontext.8 | 4 ++++
|
|
python/semanage/semanage-port.8 | 3 +++
|
|
2 files changed, 7 insertions(+)
|
|
|
|
diff --git a/python/semanage/semanage-fcontext.8 b/python/semanage/semanage-fcontext.8
|
|
index 3a96c62fda5d..a29b74994763 100644
|
|
--- a/python/semanage/semanage-fcontext.8
|
|
+++ b/python/semanage/semanage-fcontext.8
|
|
@@ -100,6 +100,10 @@ execute the following commands.
|
|
# semanage fcontext \-a \-e /home /disk6/home
|
|
# restorecon \-R \-v /disk6
|
|
|
|
+Add file-context with MLS range s0:c0.c255 for /secure directory (MLS/MCS systems only)
|
|
+# semanage fcontext \-a \-t admin_home_t \-r s0:c0.c255 "/secure(/.*)?"
|
|
+# restorecon \-R \-F \-v /secure
|
|
+
|
|
.SH "SEE ALSO"
|
|
.BR selinux (8),
|
|
.BR semanage (8),
|
|
diff --git a/python/semanage/semanage-port.8 b/python/semanage/semanage-port.8
|
|
index c6048660ca21..0df442901378 100644
|
|
--- a/python/semanage/semanage-port.8
|
|
+++ b/python/semanage/semanage-port.8
|
|
@@ -61,6 +61,9 @@ Allow Apache to listen on tcp port 81 (i.e. assign tcp port 81 label http_port_t
|
|
# semanage port \-a \-t http_port_t \-p tcp 81
|
|
Allow sshd to listen on tcp port 8991 (i.e. assign tcp port 8991 label ssh_port_t, which sshd is allowed to listen on)
|
|
# semanage port \-a \-t ssh_port_t \-p tcp 8991
|
|
+Add a custom port 9999 with MLS range s0:c0.c255 (MLS/MCS systems only). Verify with seinfo.
|
|
+# semanage port \-a \-t http_port_t \-p tcp \-r s0:c0.c255 9999
|
|
+# seinfo \-\-portcon \-x | grep 9999
|
|
|
|
.SH "SEE ALSO"
|
|
.BR selinux (8),
|
|
--
|
|
2.53.0
|
|
|