All of lore.kernel.org
 help / color / mirror / Atom feed
* Initial SIDs.
@ 2014-07-16  6:15 dE
  2014-07-16 10:41 ` Dominick Grift
  0 siblings, 1 reply; 3+ messages in thread
From: dE @ 2014-07-16  6:15 UTC (permalink / raw)
  To: selinux

I don't understanding why this's required.

As per my understanding, the SID values can be generated by the kernel 
given the security context and is internal to the kernel and independent 
of the policy, so I don't understand why do we define SID manually.

Second, I'm not sure why these initial processes require an SID in the 
1st place – my guess is cause the security context of the parent 
processes (like init) are used to compute the security context of it's 
children; so with a missing security context of the parent process, it's 
impossible to compute the security context of it's children. So a valid 
security context has to be predefined.

^ permalink raw reply	[flat|nested] 3+ messages in thread

end of thread, other threads:[~2014-07-19  5:37 UTC | newest]

Thread overview: 3+ messages (download: mbox.gz follow: Atom feed
-- links below jump to the message on this page --
2014-07-16  6:15 Initial SIDs dE
2014-07-16 10:41 ` Dominick Grift
2014-07-19  5:37   ` dE

This is an external index of several public inboxes,
see mirroring instructions on how to clone and mirror
all data and code used by this external index.