[DSE-User] SELinux sandbox policy

Mantaray mantaray_1 at cox.net
Sat Jul 10 21:59:24 UTC 2010


Hello Frank,

For Debian 5 I install the following packages to use SELinux:

	checkpolicy, policycoreutils, and selinux-utils.

These packages allow you to install and use SELinux policy, as well as
to compile your own policy.  For more information about Sandbox, you
might try contacting Dan Walsh directly or submitting the question to
the Fedora SELinux list (he regularly participates in discussions on
that list).

Good luck,
Ken.

Frank Licea wrote:
> Hello all,
>
> I'm writing a web app that requires executing untrusted C code that is
> uploaded by users. This is my first time using SELinux and I've
> successfully have it running in permissive mode on my application server
> running on Debain 5 but I am unsure of how to proceed from here.
>
> I want to execute the untrusted C code within the SELinux sandbox
> policy. Here is what I'm talking about:
>
> http://danwalsh.livejournal.com/28545.html
>
> The article explains that the policy and utils are available in the
> Fedora package: selinux-policy-3.6.12-41.fc11 and
> policycoreutils-2.0.62-12.6.fc11
>
> Does Debian have an equivalent that I can download and use? I have the
> policycoreutils package installed but I don't have /usr/bin/sandbox.
>
>
>
>
> _______________________________________________
> Selinux-user mailing list
> Selinux-user at lists.alioth.debian.org
> http://lists.alioth.debian.org/mailman/listinfo/selinux-user




More information about the Selinux-user mailing list