* trace call path
@ 2002-01-16 18:46 Shaun Savage
2002-01-16 20:05 ` Stephen Smalley
0 siblings, 1 reply; 2+ messages in thread
From: Shaun Savage @ 2002-01-16 18:46 UTC (permalink / raw)
To: SELinux
HI
I have a problem with running iptables (using ipchains.te) from the
command line, context root:sysadm_r:sysadm_t. I get no "denied" in the
log. I am baffled.
I put an "auditallow sysadm_t ipchains_exec_t:file execute; in the
ipchains.te, I see the execute.
the "auditallow sysadm_t ipchains_t:process transition;" I don't see that.
on the command line is see "permission denied"
I have also added "role sysadm_t types { ipchains_t}; "
,"domain_auto_trans(sysadm_t,ipchains_exec_t,ipchains_t)"
So I want to learn some debug ideas. How do you trace the calls through
selinux? Or what is the execution flow?
Shaun
--
You have received this message because you are subscribed to the selinux list.
If you no longer wish to subscribe, send mail to majordomo@tycho.nsa.gov with
the words "unsubscribe selinux" without quotes as the message.
^ permalink raw reply [flat|nested] 2+ messages in thread
* Re: trace call path
2002-01-16 18:46 trace call path Shaun Savage
@ 2002-01-16 20:05 ` Stephen Smalley
0 siblings, 0 replies; 2+ messages in thread
From: Stephen Smalley @ 2002-01-16 20:05 UTC (permalink / raw)
To: Shaun Savage; +Cc: SELinux
On Wed, 16 Jan 2002, Shaun Savage wrote:
> I have also added "role sysadm_t types { ipchains_t}; "
I assume that you mean 'role sysadm_r types { ipchains_t };'.
If not, then this is the error.
--
Stephen D. Smalley, NAI Labs
ssmalley@nai.com
--
You have received this message because you are subscribed to the selinux list.
If you no longer wish to subscribe, send mail to majordomo@tycho.nsa.gov with
the words "unsubscribe selinux" without quotes as the message.
^ permalink raw reply [flat|nested] 2+ messages in thread
end of thread, other threads:[~2002-01-16 20:05 UTC | newest]
Thread overview: 2+ messages (download: mbox.gz follow: Atom feed
-- links below jump to the message on this page --
2002-01-16 18:46 trace call path Shaun Savage
2002-01-16 20:05 ` Stephen Smalley
This is an external index of several public inboxes,
see mirroring instructions on how to clone and mirror
all data and code used by this external index.