All of lore.kernel.org
 help / color / mirror / Atom feed
* ps aux output under sysadm context in refpolicy
@ 2008-02-21 21:22 Jeremiah Jahn
  2008-02-22 14:35 ` Stephen Smalley
  0 siblings, 1 reply; 10+ messages in thread
From: Jeremiah Jahn @ 2008-02-21 21:22 UTC (permalink / raw)
  To: selinux

[-- Attachment #1: Type: text/plain, Size: 799 bytes --]

I'm having a heck of a time limiting the ps aux output to show only what
I think sysadm should be able to see.

I have a number of types that are running and I get a ptrace denied, but
sysadm can still see the process. I'm really not sure why this is the
case. I've set all the build options correctly, ie left the defaults,
the booleans are set to no. Somewhere there is something going on that
lets sysadm see all of this stuff, and I just can't find it.

According to apol there is not way for me to read the proc files as
sysadm. What Am I missing, or where should I look.

thanx,
-jj-



He thought he saw an albatross That fluttered 'round the lamp. He looked
again and saw it was A penny postage stamp. "You'd best be getting
home," he said, "The nights are rather damp."

[-- Attachment #2: This is a digitally signed message part --]
[-- Type: application/pgp-signature, Size: 189 bytes --]

^ permalink raw reply	[flat|nested] 10+ messages in thread

end of thread, other threads:[~2008-02-22 19:51 UTC | newest]

Thread overview: 10+ messages (download: mbox.gz follow: Atom feed
-- links below jump to the message on this page --
2008-02-21 21:22 ps aux output under sysadm context in refpolicy Jeremiah Jahn
2008-02-22 14:35 ` Stephen Smalley
2008-02-22 14:56   ` Jeremiah Jahn
2008-02-22 15:01     ` Stephen Smalley
2008-02-22 15:19       ` Jeremiah Jahn
2008-02-22 15:49         ` Stephen Smalley
2008-02-22 15:33       ` Gen_require scoping? selinux
2008-02-22 17:11         ` Daniel J Walsh
2008-02-22 19:13           ` selinux
2008-02-22 19:50             ` Daniel J Walsh

This is an external index of several public inboxes,
see mirroring instructions on how to clone and mirror
all data and code used by this external index.