[systemd-devel] [PATCH] selinux: figure out selinux context applied on exec() before closing all fds
lennart at poettering.net
Wed Dec 3 18:02:09 PST 2014
On Wed, 12.11.14 13:53, Michal Sekletar (msekleta at redhat.com) wrote:
> We need original socket_fd around otherwise mac_selinux_get_child_mls_label
> fails with -EINVAL return code. Also don't call setexeccon twice but rather pass
> context value of SELinuxContext option as an extra argument.
I trust this is tested and does the right thing, my SELinux-fu is way
too limited to really understand MLS and all this fancy stuff, in
order to verify that this is all OK.
Lennart Poettering, Red Hat
More information about the systemd-devel