All of lore.kernel.org
 help / color / mirror / Atom feed
* Listing restrictions on roles.
@ 2014-07-02  5:07 dE
  2014-07-03  9:39 ` Daniel J Walsh
  0 siblings, 1 reply; 4+ messages in thread
From: dE @ 2014-07-02  5:07 UTC (permalink / raw)
  To: selinux

There seem to exist additional non-transition restrictions on roles 
which define when will a process be able to execute as a certain role.

For e.g. a process which runs from a login shell cannot have system_r 
role. How do I list such rules?

Looking at role transition rules, a transition to system_r should be 
allowed --

sesearch --role_allow | grep system_r\;
...
allow unconfined_r system_r;
...

And the sudo process runs as unconfined_r --

ps auxZ | grep sudo
system_u:unconfined_r:unconfined_t:s0 root 669  0.0  0.4 206860 3356 
pts/1    S+   10:28   0:00 sudo -r unconfined_r nano

But sudo -r system_r nano fails.

^ permalink raw reply	[flat|nested] 4+ messages in thread

end of thread, other threads:[~2014-07-07 15:23 UTC | newest]

Thread overview: 4+ messages (download: mbox.gz follow: Atom feed
-- links below jump to the message on this page --
2014-07-02  5:07 Listing restrictions on roles dE
2014-07-03  9:39 ` Daniel J Walsh
2014-07-05 16:41   ` dE
2014-07-07 15:23     ` Daniel J Walsh

This is an external index of several public inboxes,
see mirroring instructions on how to clone and mirror
all data and code used by this external index.