All of lore.kernel.org
 help / color / mirror / Atom feed
From: sven.vermeulen@siphos.be (Sven Vermeulen)
To: refpolicy@oss.tresys.com
Subject: [refpolicy] Kernel-triggered scripts
Date: Sat, 8 Dec 2012 22:18:07 +0100	[thread overview]
Message-ID: <20121208211807.GA7476@siphos.be> (raw)

Hi guys,

One of the init systems that Gentoo supports uses kernel-triggered scripts
for managing cgroups (I'm pretty sure others do a similar thing). If the
script is labeled as bin_t, the execution of the script runs as kernel_t.

I'd like to set up a proper domain transition for this, but I'm not sure
where to position it exactly. It is part of the init system, but it has
little to do with "init" by itself, so I'm inclined to put it in either a
separate module, or inside the portage module.

What do other distributions do with kernel-triggered scripts? Let them run
in the kernel_t domain? The domain runs as unconfined if you support
unconfined domains, so it is possible most distributions have less impact on
such things).

Wkr,
	Sven Vermeulen

             reply	other threads:[~2012-12-08 21:18 UTC|newest]

Thread overview: 2+ messages / expand[flat|nested]  mbox.gz  Atom feed  top
2012-12-08 21:18 Sven Vermeulen [this message]
2012-12-10 15:02 ` [refpolicy] Kernel-triggered scripts Daniel J Walsh

Reply instructions:

You may reply publicly to this message via plain-text email
using any one of the following methods:

* Save the following mbox file, import it into your mail client,
  and reply-to-all from there: mbox

  Avoid top-posting and favor interleaved quoting:
  https://en.wikipedia.org/wiki/Posting_style#Interleaved_style

* Reply using the --to, --cc, and --in-reply-to
  switches of git-send-email(1):

  git send-email \
    --in-reply-to=20121208211807.GA7476@siphos.be \
    --to=sven.vermeulen@siphos.be \
    --cc=refpolicy@oss.tresys.com \
    /path/to/YOUR_REPLY

  https://kernel.org/pub/software/scm/git/docs/git-send-email.html

* If your mail client supports setting the In-Reply-To header
  via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line before the message body.
This is an external index of several public inboxes,
see mirroring instructions on how to clone and mirror
all data and code used by this external index.