[tomoyo-users-en 708] Re: Set profile in a child process

Back to archive index
Tetsuo Handa pengu****@i-lov*****
Wed Jun 5 20:57:39 JST 2019


Hello.

Thank you for using TOMOYO.

On 2019/06/05 20:47, Pannbacker, Ole wrote:
> 
> 
> I recently started using TOMOYO and tried to set sshd to learning mode, however the child processes stayed on mode 0.

Profile number of current domain is inherited to a child domain
only when that child domain was newly created by current domain.

That is, if you changed profile number of domain for sshd process
when domains for child processes already exist, profile number of
domains for child processes does not change.

In this case, please explicitly change profile number of domains
for child processes.

> 
> 
> 5: 1 +- sshd (4093) <kernel> /usr/sbin/sshd
> 6: 0 +- bash (4101) <kernel> /usr/sbin/sshd /bin/bash
> 7: 0 +- tomoyo-editpoli (4125) <kernel> /usr/sbin/sshd /bin/bash /usr/sbin/tomoyo-editpolicy
> 8: 1 +- sshd (4171) <kernel> /usr/sbin/sshd
> 9: 0 +- bash (4176) <kernel> /usr/sbin/sshd /bin/bash
> 
> 
> Kind regards
> 
> Ole Pannbacker
> 
> 
> _______________________________________________
> tomoyo-users-en mailing list
> tomoy****@lists*****
> https://lists.osdn.me/mailman/listinfo/tomoyo-users-en
> 




More information about the tomoyo-users-en mailing list
Back to archive index