Research Menu

.
Skip Search Box

SELinux Mailing List

initrc_t has no execmod in targeted policy

From: Vladimir Simonov <Vladimir.Simonov_at_acronis.com>
Date: Mon, 06 Feb 2006 10:33:38 +0300


Hi all,

Trying to launch my network daemon fron init.d on Fedora Core 4 I see "avc: denied { execmod } ..." in audit.log. The daemon loads some shared libraries via dlopen. If I guessed right, code relocation at load time modifies code segment and violates "no execmod for initrc_t" rile.

The questions:
1. Is my guess correct?
2. If yes, should it be considered as policy drawback (FC4 uses policy.19) or I'm missing something? 3. How to add execmod to system_u:system_r:initrc_t type without full policy rebuild?

Best regards
Vladimir Simonov

--
This message was distributed to subscribers of the selinux mailing list.
If you no longer wish to subscribe, send mail to majordomo@tycho.nsa.gov with
the words "unsubscribe selinux" without quotes as the message.
Received on Mon 6 Feb 2006 - 02:33:48 EST
 

Date Posted: Jan 15, 2009 | Last Modified: Jan 15, 2009 | Last Reviewed: Jan 15, 2009

 
bottom

National Security Agency / Central Security Service