selinux policy UBAC question

Roberto Sassu roberto.sassu at polito.it
Mon Oct 25 12:45:54 UTC 2010


Hi all

i'm using the selinux policy shipped with Fedora 13 and UBAC turned on.
I removed the unconfined package and i noted the unconfined_t domain with
unconfined_u user is unable to access a file with another selinux user.
I tried to build a custom module which contains the line:

ubac_process_exempt(unconfined_t)

but this does not solve the issue. How do i configure the policy to allow some
domains to circumvent the UBAC enforcement?
Thanks in advance for replies.

Roberto Sassu


More information about the selinux mailing list