[systemd-devel] [PATCH] selinux: figure out selinux context applied on exec() before closing all fds

Lennart Poettering lennart at poettering.net
Wed Dec 3 18:02:09 PST 2014

On Wed, 12.11.14 13:53, Michal Sekletar (msekleta at redhat.com) wrote:

> We need original socket_fd around otherwise mac_selinux_get_child_mls_label
> fails with -EINVAL return code. Also don't call setexeccon twice but rather pass
> context value of SELinuxContext option as an extra argument.

OK, applied!

I trust this is tested and does the right thing, my SELinux-fu is way
too limited to really understand MLS and all this fancy stuff, in
order to verify that this is all OK.



Lennart Poettering, Red Hat

More information about the systemd-devel mailing list