Remix.run Logo
codedokode 19 hours ago

How do you write SELinux policies to allow reading only certain files in /proc, where process IDs are not known ahead? I ended up writing my own FUSE-based /proc emulation. The facilities are there, but it feels like writing your own OS.

jolmg 19 hours ago | parent [-]

What kind of use-case do you have for that? I suppose whatever it is, you could also e.g. write a privileged service that checks those files with whatever security policy you need. Your client wouldn't have direct access to /proc.

Another option may be to set up a container or PID namespace and give your tool direct access to that /proc.

Regarding SELinux, looking at https://unix.stackexchange.com/questions/767564/selinux-deni...

> the entries under /proc/<pidnr>/ are running under the respective pid's domain

It also seems doable, since you can differentiate which PID directory belongs to what by the domain.