Research Menu

.
Skip Search Box

SELinux Mailing List

Re: dynamic context transitions

From: Luke Kenneth Casson Leighton <lkcl_at_lkcl.net>
Date: Thu, 25 Nov 2004 21:35:19 +0000


On Fri, Nov 26, 2004 at 06:48:57AM +1100, Russell Coker wrote:

> If a running process has been cracked and does not have the same PID as the
> original copy then the stop script will not stop it.

 i don't know if it's worthwhile but has anyone given serious  consideration to adding the pid into the selinux mix as a  permission to check operations against? (requiring that a pid  somehow be stored at runtime in the selinux policy of course).

 l.

--
This message was distributed to subscribers of the selinux mailing list.
If you no longer wish to subscribe, send mail to majordomo@tycho.nsa.gov with
the words "unsubscribe selinux" without quotes as the message.
Received on Thu 25 Nov 2004 - 16:24:56 EST
 

Date Posted: Jan 15, 2009 | Last Modified: Jan 15, 2009 | Last Reviewed: Jan 15, 2009

 
bottom

National Security Agency / Central Security Service