All of lore.kernel.org
 help / color / mirror / Atom feed
* [refpolicy] Kernel-triggered scripts
@ 2012-12-08 21:18 Sven Vermeulen
  2012-12-10 15:02 ` Daniel J Walsh
  0 siblings, 1 reply; 2+ messages in thread
From: Sven Vermeulen @ 2012-12-08 21:18 UTC (permalink / raw)
  To: refpolicy

Hi guys,

One of the init systems that Gentoo supports uses kernel-triggered scripts
for managing cgroups (I'm pretty sure others do a similar thing). If the
script is labeled as bin_t, the execution of the script runs as kernel_t.

I'd like to set up a proper domain transition for this, but I'm not sure
where to position it exactly. It is part of the init system, but it has
little to do with "init" by itself, so I'm inclined to put it in either a
separate module, or inside the portage module.

What do other distributions do with kernel-triggered scripts? Let them run
in the kernel_t domain? The domain runs as unconfined if you support
unconfined domains, so it is possible most distributions have less impact on
such things).

Wkr,
	Sven Vermeulen

^ permalink raw reply	[flat|nested] 2+ messages in thread

end of thread, other threads:[~2012-12-10 15:02 UTC | newest]

Thread overview: 2+ messages (download: mbox.gz follow: Atom feed
-- links below jump to the message on this page --
2012-12-08 21:18 [refpolicy] Kernel-triggered scripts Sven Vermeulen
2012-12-10 15:02 ` Daniel J Walsh

This is an external index of several public inboxes,
see mirroring instructions on how to clone and mirror
all data and code used by this external index.