SELinuxDenyPtrace: Write, compile, run, but don't debug applications?

Frank Ch. Eigler fche at redhat.com
Sun Apr 8 20:59:40 UTC 2012


John Reiser <jreiser at bitwagon.com> writes:

> [...]
> According to this bugzilla Comment
>    https://bugzilla.redhat.com/show_bug.cgi?id=786878#c27
> Fedora 17 Alpha turned on denyPtrace (as default) by mistake.

That's not how I read #c27.  The flag was turned off during alpha by
mistake and that it would be on in the beta, on purpose.  It is the
post-alpha pre-beta code that mjw and others have been testing.


> According to other Comments to that same bug, the fix might involve
> allowing by default only PTRACE_ME [...]

That sounded all like future work.


- FChE


More information about the devel mailing list