All of lore.kernel.org
 help / color / mirror / Atom feed
From: "Lorenzo Hernández García-Hierro" <lorenzo@gnu.org>
To: russell@coker.com.au
Cc: "Villalovos, John L" <john.l.villalovos@intel.com>,
	Stephen Smalley <sds@epoch.ncsc.mil>,
	selinux@tycho.nsa.gov
Subject: Re: Advice on bringing up SE Linux
Date: Thu, 03 Feb 2005 14:42:50 +0100	[thread overview]
Message-ID: <1107438170.3754.162.camel@localhost.localdomain> (raw)
In-Reply-To: <200502031820.54692.russell@coker.com.au>

[-- Attachment #1: Type: text/plain, Size: 2156 bytes --]

El jue, 03-02-2005 a las 18:20 +1100, Russell Coker escribió:
> On Wednesday 02 February 2005 07:51, "Villalovos, John L" 
> <john.l.villalovos@intel.com> wrote:
> > > /sbin/init is what normally loads the policy during startup.  Are you
> > > using the modified /sbin/init (included in Fedora)?  What is in your
> > > /etc/selinux/config?
> >
> > Okay.  We are using Busybox for the init.  So it does not have the SE
> > Linux stuff in it.
> 
> The upstream developer of busybox was accepting of SE Linux patches, I had 
> some SE Linux patches in the busybox CVS at one time (not sure if they are 
> still there).  If I get a bit of spare time I'll do some more work on Busybox 
> SE Linux support, it's good to have for recovery purposes and I think I've 
> still got some patches hanging around that I never got sorted out properly 
> for release.
> 
> Also you may want to check out the paper I presented at OLS on getting SE 
> Linux running on iPaQ's, the stuff about wrapping busybox etc will probably 
> be of interest to you.
> 
> If you get the JFFS2 support written I'll be very interested, I have a couple 
> of iPaQ's I want to get running SE Linux again.

I've been studying the code from both mtd and Linux-2.6 sources of
JFFS2	.
Also talked with some people from the Gentoo project that could help
with it.
We can try to bring up a work module on the SELinux CVS and start doing
something there.

AFAIK, and from the conversations I had with one of the Hardened Gentoo
guys (solar), xattr takes an additional 32bytes or 1 block which makes
it an overhead that needs to be studied, and noticeable on devices with
*limited* storage capacity, such as iPAQs.

Anyways, I would like to discuss this with some kernel hackers before
getting into the job.
The best start is having such device for testing, and I don't own an
iPAQ, also using machine emulators is pretty a crap solution, in my
opinion.
(I have no experience working with ARM, so, sure I'm forgetting
something)

Cheers,
-- 
Lorenzo Hernández García-Hierro <lorenzo@gnu.org> 
[1024D/6F2B2DEC] & [2048g/9AE91A22][http://tuxedo-es.org]

[-- Attachment #2: Esta parte del mensaje está firmada digitalmente --]
[-- Type: application/pgp-signature, Size: 189 bytes --]

  reply	other threads:[~2005-02-03 13:43 UTC|newest]

Thread overview: 10+ messages / expand[flat|nested]  mbox.gz  Atom feed  top
2005-02-01 20:51 Advice on bringing up SE Linux Villalovos, John L
2005-02-03  7:20 ` Russell Coker
2005-02-03 13:42   ` Lorenzo Hernández García-Hierro [this message]
  -- strict thread matches above, loose matches on Subject: below --
2005-02-03 21:49 Villalovos, John L
2005-02-01 20:50 Villalovos, John L
2005-02-02 13:02 ` Stephen Smalley
2005-02-01 18:51 Villalovos, John L
2005-02-01 19:00 ` Stephen Smalley
2005-02-01 19:24   ` Stephen Smalley
2005-02-03  7:13     ` Russell Coker

Reply instructions:

You may reply publicly to this message via plain-text email
using any one of the following methods:

* Save the following mbox file, import it into your mail client,
  and reply-to-all from there: mbox

  Avoid top-posting and favor interleaved quoting:
  https://en.wikipedia.org/wiki/Posting_style#Interleaved_style

* Reply using the --to, --cc, and --in-reply-to
  switches of git-send-email(1):

  git send-email \
    --in-reply-to=1107438170.3754.162.camel@localhost.localdomain \
    --to=lorenzo@gnu.org \
    --cc=john.l.villalovos@intel.com \
    --cc=russell@coker.com.au \
    --cc=sds@epoch.ncsc.mil \
    --cc=selinux@tycho.nsa.gov \
    /path/to/YOUR_REPLY

  https://kernel.org/pub/software/scm/git/docs/git-send-email.html

* If your mail client supports setting the In-Reply-To header
  via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line before the message body.
This is an external index of several public inboxes,
see mirroring instructions on how to clone and mirror
all data and code used by this external index.