All of lore.kernel.org
 help / color / mirror / Atom feed
* I cannot change my shell context
@ 2009-09-02  3:07 zheyeung
  2009-09-02 13:59 ` Dennis Wronka
  0 siblings, 1 reply; 4+ messages in thread
From: zheyeung @ 2009-09-02  3:07 UTC (permalink / raw)
  To: fedora-selinux-list; +Cc: selinux

[-- Attachment #1: Type: text/plain, Size: 1516 bytes --]

hi , every body ,I install selinux-policy-targeted in my F11,and run in enforce mode.
now I want to change selinux context of /tmp/test,but  failed.I thought current shell domain was unconfined_t. then I intend to change my shell context to root:sysadm_r: sysadm_t ,but also failed. 
my project team plan to develop selinux policy for our system based on selinux-policy.src.rpm. I guess is  this package have not been developed? If it has been developed ,why I cannot change to sysadm_r: sysadm_t? 

----------------------------------------------------------------------------

[root@localhost ~]# ls -lZ /tmp/testselinux
root root unconfined_u:object_r:user_t:user_tmp_t: s0 /tmp/testselinux

[root@localhost ~]#chcon unconfined_u:object_r:mytest_t /tmp/testselinux
chcon:failed to change context of '/tmp/testselinux' to 'unconfined_u:object_r:testselinux: s0 : permission denied

## here mytest_t defined in myapp.pp,which has successfully loaded by "semodule -i myapp.pp"

[root@localhost ~]# newrole -r sysadm_r -t sysadm_t
unconfined_u:unconfined_r:unconfined_t: s0 is not valid context

[root@localhost ~]# semanage login -m -s root -r s0-s0:c0.c1023 root

after reboot, graphic terminal cannot run. audit says that system_u:system_r: xdm_t require "read" permission for system_u:object_r:httpd_sys_content_t.

[root@localhost ~]# id
context= root:unconfined_r:unconfined_t: s0-s0:c0-c1023

[root@localhost ~]#  newrole -r sysadm_r -t sysadm_t
failed to exec shell: permission denied
2009-09-02 



zheyeung 

[-- Attachment #2: Type: text/html, Size: 2603 bytes --]

^ permalink raw reply	[flat|nested] 4+ messages in thread
[parent not found: <CIEOKAFOMGPNJIPMMMAHAEDJCCAA.remmolt@zwartsenberg.eu>]

end of thread, other threads:[~2009-09-04 13:02 UTC | newest]

Thread overview: 4+ messages (download: mbox.gz follow: Atom feed
-- links below jump to the message on this page --
2009-09-02  3:07 I cannot change my shell context zheyeung
2009-09-02 13:59 ` Dennis Wronka
     [not found] <CIEOKAFOMGPNJIPMMMAHAEDJCCAA.remmolt@zwartsenberg.eu>
2009-09-03 14:59 ` Dennis Wronka
2009-09-04 13:02   ` Daniel J Walsh

This is an external index of several public inboxes,
see mirroring instructions on how to clone and mirror
all data and code used by this external index.