Re: socket activation selinux context on create

[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]

 



On Fr, 02.09.22 09:04, Ted Toth (txtoth@xxxxxxxxx) wrote:

> I have set the type for the port in question using the 'semanage port'
> command so the loaded policy has a type which systemd should use when
> calling setsockcreatecon. It is my opinion that
> socket_determine_selinux_label function should query policy for the
> port type and if it has been set use it and if not fallback to its
> current behavior.

Sure, patch very welcome.

SELinux code really requires external contributions, none of the core
developers know SELinux too well to do feel confident to implement
that.

(consider filing an RFE issue on github, so that this is tracked)

Lennart

--
Lennart Poettering, Berlin



[Index of Archives]     [LARTC]     [Bugtraq]     [Yosemite Forum]     [Photo]

  Powered by Linux