Re: Allow file access to two different domains
Zdenek Pytela <[email protected]> Mon, 24 Oct 2022 13:45:36 +0200
| Newsgroups | gmane.linux.redhat.fedora.selinux |
|---|---|
| Message-ID | <CAO4UijBDN8BCMswBSeKRdvRPO_Nw0PLpJZ9GJd1EeBQuK8OUaQ@mail.gmail.com> |
On Sat, Oct 22, 2022 at 9:16 PM Gionatan Danti <[email protected]> wrote: > Hi all, > as one file/dir can have one and only one selinux label, I wonder if/how > one can allow processes from different domains to access the same > files/dirs. > > I know that for specific executable and directory one can use the > appropriate bools, for example samba_enable_home_dirs enables smbd to > read/write home_root_t types. I also know that one can create and load a > custom policy to allow the required access. > > However, I wonder if an easier approach exists to let processes with > different domains to access the same set of files or directories. > > Any clue? > Thanks. Hi Danti, I am not sure if I am getting you well, please add an example if not. For accessing types from other modules, interfaces are used, refer to https://github.com/fedora-selinux/selinux-policy/blob/rawhide/policy/modules/contrib/samba.te#L524 https://github.com/fedora-selinux/selinux-policy/blob/rawhide/policy/modules/contrib/snmp.te#L146 > > -- > Danti Gionatan > Supporto Tecnico > Assyoma S.r.l. - www.assyoma.it > email: [email protected] - [email protected] > GPG public key ID: FF5F32A8 > _______________________________________________ > selinux mailing list -- [email protected] > To unsubscribe send an email to [email protected] > Fedora Code of Conduct: > https://docs.fedoraproject.org/en-US/project/code-of-conduct/ > List Guidelines: https://fedoraproject.org/wiki/Mailing_list_guidelines > List Archives: > https://lists.fedoraproject.org/archives/list/[email protected] > Do not reply to spam, report it: > https://pagure.io/fedora-infrastructure/new_issue > -- Zdenek Pytela Security SELinux team _______________________________________________ selinux mailing list -- [email protected] To unsubscribe send an email to [email protected] Fedora Code of Conduct: https://docs.fedoraproject.org/en-US/project/code-of-conduct/ List Guidelines: https://fedoraproject.org/wiki/Mailing_list_guidelines List Archives: https://lists.fedoraproject.org/archives/list/[email protected] Do not reply to spam, report it: https://pagure.io/fedora-infrastructure/new_issue