All of lore.kernel.org
 help / color / mirror / Atom feed
* security_bounded_transition fails
@ 2015-12-18  6:12 Hannu Savolainen
  2015-12-18  8:46 ` Dominick Grift
  2015-12-18 13:39 ` Stephen Smalley
  0 siblings, 2 replies; 7+ messages in thread
From: Hannu Savolainen @ 2015-12-18  6:12 UTC (permalink / raw)
  To: selinux

Hi,

I'm having a problem with a multithreaded application. It does lengthy  initialization in advance under relatively privileged context and then switches to a less privileged one after the moment when the actual request arrives. After that it will create a chrooted container and join all threads to a new SELinux context.

However the transition fails with audit message "op=security_bounded_transition result=denied oldcontext=old_context newcontext=new_context".

Is there any policy rule that could be used to fix this or is this just not supported?

Best regards,

Hannu

^ permalink raw reply	[flat|nested] 7+ messages in thread

end of thread, other threads:[~2015-12-18 18:53 UTC | newest]

Thread overview: 7+ messages (download: mbox.gz / follow: Atom feed)
-- links below jump to the message on this page --
2015-12-18  6:12 security_bounded_transition fails Hannu Savolainen
2015-12-18  8:46 ` Dominick Grift
2015-12-18 10:20   ` Dominick Grift
2015-12-18 10:45     ` Dominick Grift
     [not found]       ` <B295455A1EDEE541907F53334176EF68070003D0@lhreml504-mbx>
2015-12-18 15:05         ` Dominick Grift
2015-12-18 18:53           ` Stephen Smalley
2015-12-18 13:39 ` Stephen Smalley

This is an external index of several public inboxes,
see mirroring instructions on how to clone and mirror
all data and code used by this external index.