{
    "mode": "man",
    "parameter": "pam_selinux",
    "section": "8",
    "url": "https://www.chedong.com/phpMan.php/man/pam_selinux/8/json",
    "generated": "2026-10-08T07:33:08Z",
    "synopsis": "pamselinux.so [open] [close] [restore] [nottys] [debug] [verbose] [selectcontext]\n[envparams] [usecurrentrange]",
    "sections": {
        "NAME": {
            "content": "pamselinux - PAM module to set the default security context\n",
            "subsections": []
        },
        "SYNOPSIS": {
            "content": "pamselinux.so [open] [close] [restore] [nottys] [debug] [verbose] [selectcontext]\n[envparams] [usecurrentrange]\n",
            "subsections": []
        },
        "DESCRIPTION": {
            "content": "pamselinux is a PAM module that sets up the default SELinux security context for the next\nexecuted process.\n\nWhen a new session is started, the opensession part of the module computes and sets up the\nexecution security context used for the next execve(2) call, the file security context for\nthe controlling terminal, and the security context used for creating a new kernel keyring.\n\nWhen the session is ended, the closesession part of the module restores old security\ncontexts that were in effect before the change made by the opensession part of the module.\n\nAdding pamselinux into the PAM stack might disrupt behavior of other PAM modules which\nexecute applications. To avoid that, pamselinux.so open should be placed after such modules\nin the PAM stack, and pamselinux.so close should be placed before them. When such a\nplacement is not feasible, pamselinux.so restore could be used to temporary restore original\nsecurity contexts.\n",
            "subsections": []
        },
        "OPTIONS": {
            "content": "open\nOnly execute the opensession part of the module.\n\nclose\nOnly execute the closesession part of the module.\n\nrestore\nIn opensession part of the module, temporarily restore the security contexts as they\nwere before the previous call of the module. Another call of this module without the\nrestore option will set up the new security contexts again.\n\nnottys\nDo not setup security context of the controlling terminal.\n\ndebug\nTurn on debug messages via syslog(3).\n\nverbose\nAttempt to inform the user when security context is set.\n\nselectcontext\nAttempt to ask the user for a custom security context role. If MLS is on, ask also for\nsensitivity level.\n\nenvparams\nAttempt to obtain a custom security context role from PAM environment. If MLS is on,\nobtain also sensitivity level. This option and the selectcontext option are mutually\nexclusive. The respective PAM environment variables are SELINUXROLEREQUESTED,\nSELINUXLEVELREQUESTED, and SELINUXUSECURRENTRANGE. The first two variables are self\ndescribing and the last one if set to 1 makes the PAM module behave as if the\nusecurrentrange was specified on the command line of the module.\n\nusecurrentrange\nUse the sensitivity level of the current process for the user context instead of the\ndefault level. Also suppresses asking of the sensitivity level from the user or obtaining\nit from PAM environment.\n",
            "subsections": []
        },
        "MODULE TYPES PROVIDED": {
            "content": "Only the session module type is provided.\n",
            "subsections": []
        },
        "RETURN VALUES": {
            "content": "PAMSUCCESS\nThe security context was set successfully.\n\nPAMSESSIONERR\nUnable to get or set a valid context.\n\nPAMUSERUNKNOWN\nThe user is not known to the system.\n\nPAMBUFERR\nMemory allocation error.\n",
            "subsections": []
        },
        "EXAMPLES": {
            "content": "auth     required  pamunix.so\nsession  required  pampermit.so\nsession  optional  pamselinux.so\n\n",
            "subsections": []
        },
        "SEE ALSO": {
            "content": "execve(2), tty(4), pam.d(5), pam(7), selinux(8)\n",
            "subsections": []
        },
        "AUTHOR": {
            "content": "pamselinux was written by Dan Walsh <dwalsh@redhat.com>.\n\nLinux-PAM                                    09/13/2023                               PAMSELINUX(8)",
            "subsections": []
        }
    },
    "summary": "pamselinux - PAM module to set the default security context",
    "flags": [],
    "examples": [
        "auth     required  pamunix.so",
        "session  required  pampermit.so",
        "session  optional  pamselinux.so"
    ],
    "see_also": [
        {
            "name": "execve",
            "section": "2",
            "url": "https://www.chedong.com/phpMan.php/man/execve/2/json"
        },
        {
            "name": "tty",
            "section": "4",
            "url": "https://www.chedong.com/phpMan.php/man/tty/4/json"
        },
        {
            "name": "pam.d",
            "section": "5",
            "url": "https://www.chedong.com/phpMan.php/man/pam.d/5/json"
        },
        {
            "name": "pam",
            "section": "7",
            "url": "https://www.chedong.com/phpMan.php/man/pam/7/json"
        },
        {
            "name": "selinux",
            "section": "8",
            "url": "https://www.chedong.com/phpMan.php/man/selinux/8/json"
        }
    ]
}