Research Menu

.
Skip Search Box

SELinux Mailing List

Re: status tool

From: Stephen Smalley <sds_at_epoch.ncsc.mil>
Date: Fri, 26 Mar 2004 09:14:04 -0500


On Thu, 2004-03-25 at 14:30, Chris PeBenito wrote:
> Over the last couple weeks I've been working on a SELinux status tool.
> I originally intended it for use as a support tool, so we could get much
> of SELinux's status in one shot. Since not being able to log in is a
> common problem, I aimed the tool to be helpful with figuring out the
> problem. After some suggestions from Russell, the result is the
> attached sestatus.

Thanks, this seems like a good idea. Did you consider readlink of /proc/pid/exe rather than read of /proc/pid/cmdline when trying to find the process for a given program? I suppose that might be a problem if they can't become root on the system, but it would offer a more reliable path for the executable. Another possibility would be to scan /proc/pid/maps.  

-- 
Stephen Smalley <sds@epoch.ncsc.mil>
National Security Agency


--
This message was distributed to subscribers of the selinux mailing list.
If you no longer wish to subscribe, send mail to majordomo@tycho.nsa.gov with
the words "unsubscribe selinux" without quotes as the message.
Received on Fri 26 Mar 2004 - 09:14:22 EST
 

Date Posted: Jan 15, 2009 | Last Modified: Jan 15, 2009 | Last Reviewed: Jan 15, 2009

 
bottom

National Security Agency / Central Security Service