Go to file
Andy Lutomirski 74d27a9733 seunshare: Try to use setcurrent before setexec
If seunshare uses PR_SET_NO_NEW_PRIVS, which certain versions of
libcap-ng set, setexeccon will cause execve to fail.  This also
makes setting selinux context the very last action taken by
seunshare prior to exec, as it may otherwise cause things to fail.

Note that this won't work without adjusting the system policy to
allow this use of setcurrent.  This rule appears to work:

    allow unconfined_t sandbox_t:process dyntransition;

although a better rule would probably relax the unconfined_t
restriction.

Signed-off-by: Andy Lutomirski <luto@amacapital.net>
2014-05-12 14:14:45 -04:00
checkpolicy Bump version and update ChangeLog for release. 2014-05-06 13:30:27 -04:00
libselinux selinux_init_load_policy: setenforce(0) if security_disable() fails 2014-05-07 15:24:35 -04:00
libsemanage Bump version and update ChangeLog for release. 2014-05-06 13:30:27 -04:00
libsepol Bump version and update ChangeLog for release. 2014-05-06 13:30:27 -04:00
policycoreutils seunshare: Try to use setcurrent before setexec 2014-05-12 14:14:45 -04:00
scripts Add make-update script and fix release script. 2013-10-31 14:34:02 -04:00
sepolgen Bump version for bug fix to sepolgen-ifgen. 2013-10-31 10:13:10 -04:00
.gitignore global: gitignore: add a couple of more editor backup filetypes 2013-02-01 12:14:57 -05:00
Makefile libselinux: additional makefile support for rubywrap 2012-06-28 11:21:16 -04:00
README Adjust build instructions to clarify x86_64 vs x86. 2013-10-30 12:51:19 -04:00

README

To build and install everything under a private directory, run:
make DESTDIR=~/obj install install-pywrap

To install as the default system libraries and binaries
(overwriting any previously installed ones - dangerous!),
on x86_64, run:
make LIBDIR=/usr/lib64 SHLIBDIR=/lib64 install install-pywrap relabel
or on x86 (32-bit), run:
make install install-pywrap relabel

This may render your system unusable if the upstream SELinux userspace
lacks library functions or other dependencies relied upon by your
distribution.  If it breaks, you get to keep both pieces.