All of lore.kernel.org
 help / color / mirror / Atom feed
* I think this is a bug in the kernel
@ 2008-05-09 13:47 Daniel J Walsh
  2008-05-09 14:14 ` Stephen Smalley
                   ` (2 more replies)
  0 siblings, 3 replies; 11+ messages in thread
From: Daniel J Walsh @ 2008-05-09 13:47 UTC (permalink / raw)
  To: SE Linux

-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA1

https://bugzilla.redhat.com/show_bug.cgi?id=445709	

libvirtd is clearly not ptracing the unconfined_t domain.  It is
problably looking under /proc for some information about the app that is
communicating with it.  It might be reading unconfined_t environment.  I
am not sure, but we generate a ptrace and stop the app from working.  My
only choice is to allow virtd to ptrace unconfined_t processes which is
not a good idea.  This has to be fixes in the kernel.

Dan
-----BEGIN PGP SIGNATURE-----
Version: GnuPG v1.4.9 (GNU/Linux)
Comment: Using GnuPG with Fedora - http://enigmail.mozdev.org

iEYEARECAAYFAkgkVg4ACgkQrlYvE4MpobPCvwCfa/iBjD3h2dFnEDvB39c8db0a
ITAAn1ktC480Tvx6lgx01ufjPNeQGOxC
=7O2c
-----END PGP SIGNATURE-----

--
This message was distributed to subscribers of the selinux mailing list.
If you no longer wish to subscribe, send mail to majordomo@tycho.nsa.gov with
the words "unsubscribe selinux" without quotes as the message.

^ permalink raw reply	[flat|nested] 11+ messages in thread

end of thread, other threads:[~2008-05-12 13:08 UTC | newest]

Thread overview: 11+ messages (download: mbox.gz follow: Atom feed
-- links below jump to the message on this page --
2008-05-09 13:47 I think this is a bug in the kernel Daniel J Walsh
2008-05-09 14:14 ` Stephen Smalley
2008-05-09 14:16 ` Daniel J Walsh
2008-05-09 14:25   ` Stephen Smalley
2008-05-09 14:30     ` Daniel J Walsh
2008-05-09 14:34       ` Stephen Smalley
2008-05-09 14:42         ` Daniel J Walsh
2008-05-09 14:53           ` Stephen Smalley
2008-05-09 15:03             ` Daniel J Walsh
2008-05-12 12:26 ` Daniel J Walsh
2008-05-12 13:08   ` Stephen Smalley

This is an external index of several public inboxes,
see mirroring instructions on how to clone and mirror
all data and code used by this external index.