-
Bug
-
Resolution: Done
-
Normal
-
None
-
None
As follow-on work to USHIFT-1568, we should add a test which verifies that it's not possible to utilize the privileges of another domain in order to do more than what's possible inside a restricted domain.
An example of this would be running the `foo` binary, which might have policy which might instruct SELinux to automatically transition to the `bar` domain when foo is executed from a process running in the `foobar` domain. We should be able to find policy which might facilitate this via `sesearch`.
- is cloned by
-
USHIFT-1755 Add test which verifies that it's not possible to utilize the privilieges of another domain in order to do more than what's possible inside a restricted domain
- Closed
- links to