| ▲ | codedokode 19 hours ago | |
How do you write SELinux policies to allow reading only certain files in /proc, where process IDs are not known ahead? I ended up writing my own FUSE-based /proc emulation. The facilities are there, but it feels like writing your own OS. | ||
| ▲ | jolmg 19 hours ago | parent [-] | |
What kind of use-case do you have for that? I suppose whatever it is, you could also e.g. write a privileged service that checks those files with whatever security policy you need. Your client wouldn't have direct access to /proc. Another option may be to set up a container or PID namespace and give your tool direct access to that /proc. Regarding SELinux, looking at https://unix.stackexchange.com/questions/767564/selinux-deni... > the entries under /proc/<pidnr>/ are running under the respective pid's domain It also seems doable, since you can differentiate which PID directory belongs to what by the domain. | ||