Explain NNP transitions - #53
Closed
WOnder93 wants to merge 1 commit into
Closed
Conversation
Provide a brief explanation of the NNP concept and how it realtes to SELinux transitions to help guide people deciding whether to allow the nnp_transtion permission or not. Signed-off-by: Ondrej Mosnacek <omosnace@redhat.com>
stephensmalley
self-requested a review
September 10, 2025 15:01
stephensmalley
approved these changes
Sep 10, 2025
stephensmalley
left a comment
Member
There was a problem hiding this comment.
LGTM. Most common use case is allowing daemons to still transition to their own domains when executed with NNP set or from a nosuid mount. SELinux domain transitions are rarely if ever exact subsets of the calling domain's permissions since they at least differ wrt their permissions to their own executable, tmp, and other derived types.
Member
|
Merged via manual push. Thanks! |
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Provide a brief explanation of the NNP concept and how it realtes to SELinux transitions to help guide people deciding whether to allow the nnp_transtion permission or not.
It has been pointed out to me that the semantics behind the
nnp_transitionpermission are not obvious and that it would help to have some documentation on it, so I tried to to add it here. I'm not quite sure if it's sufficiently clear and correct, so would welcome feedback.Cc @zpytela @stephensmalley