All of lore.kernel.org
 help / color / mirror / Atom feed
* launching apps at level (MLS) and polyinstantiation
@ 2007-04-27 18:41 Ted X Toth
  2007-04-27 19:01 ` Stephen Smalley
  0 siblings, 1 reply; 22+ messages in thread
From: Ted X Toth @ 2007-04-27 18:41 UTC (permalink / raw)
  To: selinux

I'm working on an application that launches other applications at a 
specified level. I have also configured polyinstantiation for a some 
directories. What I have found is that I had to make this application 
pam aware in order for the child process to get polyinstantiated 
directories. One issue is the reauthentication I've already 
authenticated why should I have to reauthenticate so that a child 
process can use polyinstantiated directories? Currently this app works 
when run as root but not as other users because the unshare call in 
pam_namespace fails for lack of permissions (CAP_SYS_ADMIN?). What do I 
need to do so that the application has this capability? I tried making 
the app setuid but that didn't help.

Ted

--
This message was distributed to subscribers of the selinux mailing list.
If you no longer wish to subscribe, send mail to majordomo@tycho.nsa.gov with
the words "unsubscribe selinux" without quotes as the message.

^ permalink raw reply	[flat|nested] 22+ messages in thread

end of thread, other threads:[~2007-05-11 18:42 UTC | newest]

Thread overview: 22+ messages (download: mbox.gz follow: Atom feed
-- links below jump to the message on this page --
2007-04-27 18:41 launching apps at level (MLS) and polyinstantiation Ted X Toth
2007-04-27 19:01 ` Stephen Smalley
2007-04-27 19:05   ` Stephen Smalley
     [not found]     ` <463360B0.7020106@gmail.com>
     [not found]       ` <1177934887.16232.7.camel@moss-spartans.epoch.ncsc.mil>
2007-04-30 14:41         ` Ted X Toth
2007-04-30 14:52           ` Stephen Smalley
2007-05-02 15:49             ` Xavier Toth
2007-05-02 16:57               ` Stephen Smalley
2007-05-02 21:42                 ` Xavier Toth
2007-05-03 12:35                   ` Stephen Smalley
2007-05-03 13:11                 ` Xavier Toth
2007-05-03 13:40                   ` Stephen Smalley
2007-05-03 13:51                     ` Xavier Toth
2007-05-03 13:49                   ` Stephen Smalley
2007-05-03 19:18                     ` Stephen Smalley
2007-05-03 21:09                       ` Darrel Goeddel
2007-05-08 17:54                         ` Stephen Smalley
2007-05-04 18:56                       ` Ted X Toth
2007-05-04 19:23                         ` Stephen Smalley
2007-05-04 20:15                           ` Ted X Toth
2007-05-08 19:11                             ` [PATCH -trunk] newrole: enable use of alternate pam configurations for running applications in a different context (Was: Re: launching apps at level (MLS) and polyinstantiation) Stephen Smalley
2007-05-08 19:54                               ` Karl MacMillan
2007-05-11 18:42                               ` Karl MacMillan

This is an external index of several public inboxes,
see mirroring instructions on how to clone and mirror
all data and code used by this external index.