Research Menu

.
Skip Search Box

SELinux Mailing List

Re: Starting applications from initrc in a user's context?

From: Stephen Smalley <sds_at_epoch.ncsc.mil>
Date: Wed, 12 Jan 2005 11:54:14 -0500


On Tue, 2005-01-04 at 05:03, Russell Coker wrote:
> Allowing the role to be changed requires adding privrole to the attributes of
> domain initrc_t. In that case either the identity system_u must be permitted
> to have the role user1_r or initrc_t also needs the privuser attribute so it
> can launch a process with a different identity.

Role changes also require a role allow rule, e.g. allow foo_r bar_r;

-- 
Stephen Smalley <sds@epoch.ncsc.mil>
National Security Agency


--
This message was distributed to subscribers of the selinux mailing list.
If you no longer wish to subscribe, send mail to majordomo@tycho.nsa.gov with
the words "unsubscribe selinux" without quotes as the message.
Received on Wed 12 Jan 2005 - 12:00:21 EST
 

Date Posted: Jan 15, 2009 | Last Modified: Jan 15, 2009 | Last Reviewed: Jan 15, 2009

 
bottom

National Security Agency / Central Security Service