Re: [RFC][PATCH 4/11] security: AppArmor - Core access controls

From: Seth Arnold
Date: Wed Apr 19 2006 - 19:18:55 EST


On Wed, Apr 19, 2006 at 07:05:08PM -0400, Rik van Riel wrote:
> Are confined processes always restricted from starting
> non-confined processes?

It is specified in policy via an unconstrained execution flag: 'ux'. Any
unconfined children can of course do whatever they wish.

Attachment: pgp00000.pgp
Description: PGP signature