All of lore.kernel.org
 help / color / mirror / Atom feed
From: Paul Moore <paul@paul-moore.com>
To: selinux@tycho.nsa.gov, vlad halilov <vlad.halilov@gmail.com>
Subject: Re: selinux and static label for sVirt
Date: Thu, 08 May 2014 16:34:26 -0400	[thread overview]
Message-ID: <1675546.P9Rft7smSN@sifl> (raw)
In-Reply-To: <CAHw9pMX-T9CHgahLLKjAfA_tOeFuKSwniikV_-ejw3GsCOQW0Q@mail.gmail.com>

On Thursday, May 08, 2014 05:45:56 PM vlad halilov wrote:
> Hello. I trying to run kvm wih mls policy on RHEL6.5 and got strange error.
> 
> Steps:
> 
> 1) installing with virtulaization software bundle;
> 2) install selinux mls and some more: xorg-x11-xauth policycoreutils-python
> selinux-policy-mls netlabel_tools setools-console;
> 3) enable mls in selinux/config, set permissive mode, autorelabel fs &
> reboot;
> 4) login by root@ssh with X (permissive mode still in effect) and create vm.
> 
> Now, after creating any vm, it can executed only with dynamic label. On
> trying to set static label (s0, s1 or any other with compartments) i got
> an error:
> 
> 2014-05-08 13:23:06.711+0000: 1607: error
> 
> :virSecuritySELinuxGenSecurityLabel:552 : unable to allocate socket
> security context 's0': Invalid argument

If you are going to use static labels with sVirt you need to specify the 
entire SELinux label and not just the MLS field.  I recommend searching for 
the "Red Hat Enterprise Linux 6 Virtualization Security Guide" for more 
information on using sVirt with RHEL6.

-- 
paul moore
www.paul-moore.com

  reply	other threads:[~2014-05-08 20:34 UTC|newest]

Thread overview: 3+ messages / expand[flat|nested]  mbox.gz  Atom feed  top
2014-05-08 13:45 selinux and static label for sVirt vlad halilov
2014-05-08 20:34 ` Paul Moore [this message]
2014-05-09  5:33   ` vlad halilov

Reply instructions:

You may reply publicly to this message via plain-text email
using any one of the following methods:

* Save the following mbox file, import it into your mail client,
  and reply-to-all from there: mbox

  Avoid top-posting and favor interleaved quoting:
  https://en.wikipedia.org/wiki/Posting_style#Interleaved_style

* Reply using the --to, --cc, and --in-reply-to
  switches of git-send-email(1):

  git send-email \
    --in-reply-to=1675546.P9Rft7smSN@sifl \
    --to=paul@paul-moore.com \
    --cc=selinux@tycho.nsa.gov \
    --cc=vlad.halilov@gmail.com \
    /path/to/YOUR_REPLY

  https://kernel.org/pub/software/scm/git/docs/git-send-email.html

* If your mail client supports setting the In-Reply-To header
  via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line before the message body.
This is an external index of several public inboxes,
see mirroring instructions on how to clone and mirror
all data and code used by this external index.