Re: Any way to label /proc/self/mem with a different type then the process type.

[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]

 



On 08/08/2016 01:41 PM, Daniel J Walsh wrote:
> I have been requested by some container people to make this only
> readable not writable to prevent certain types of attacks on the
> 
> kernel.  No idea if this is a good idea or not.

Would require a kernel change.  Support for per-file labeling of
/proc/pid came up previously in SE for Android, so the SE for Android
todo list has an item here:

Extend SELinux /proc/pid labeling support to support derived types on
specific /proc/pid files based on both the associated task context and
the file name, e.g. name-based type transitions. This would allow
applying different restrictions to different /proc/pid files of the same
process via SELinux.

Probably should go on the SELinux kernel todo list.

_______________________________________________
Selinux mailing list
Selinux@xxxxxxxxxxxxx
To unsubscribe, send email to Selinux-leave@xxxxxxxxxxxxx.
To get help, send an email containing "help" to Selinux-request@xxxxxxxxxxxxx.



[Index of Archives]     [Selinux Refpolicy]     [Linux SGX]     [Fedora Users]     [Fedora Desktop]     [Yosemite Photos]     [Yosemite Camping]     [Yosemite Campsites]     [KDE Users]     [Gnome Users]

  Powered by Linux