All of lore.kernel.org
 help / color / mirror / Atom feed
From: Luke Kenneth Casson Leighton <lkcl@lkcl.net>
To: Chris PeBenito <pebenito@gentoo.org>
Cc: SE-Linux <selinux@tycho.nsa.gov>
Subject: Re: for bootsplash to operate correctly...
Date: Thu, 9 Sep 2004 10:57:42 +0100	[thread overview]
Message-ID: <20040909095742.GC12629@lkcl.net> (raw)
In-Reply-To: <1094698870.14648.19.camel@gorn.pebenito.net>

On Wed, Sep 08, 2004 at 11:01:11PM -0400, Chris PeBenito wrote:
> On Wed, 2004-09-08 at 18:41, Luke Kenneth Casson Leighton wrote:
> > ... i hacked in the three following permissions:
> > 
> > # this is to allow splash to write to /proc/splash
> > allow initrc_t proc_t:file { write };
> 
> > # this is for fbmngplay to do err... *clueless*
> > allow initrc_t self:capability { sys_admin };
> > 
> > i look forward to one day writing a policy for the bootsplash
> > package :)
> > 
> 
> I threw together a bootsplash policy several months ago to get the
> Gentoo LiveCD going.  I always forget about it since I only use
> bootsplash on the LiveCD.  I didn't encounter that sys_admin capability
> that you have, but it might be a result of the bootsplash setings.  We
> probably should label /proc/splash differently, now that I think about
> it.
 
 fbmngplay is the "animations" program.

 [change of topic]

 i had to disable that for other reasons: because it is running,
 it seems to lock out the /usr partition.  because of that,
 umount at shutdown actually remounts it as read-only.  because
 of _that_, stupid-debian-selinux can't stupid-remount the
 stupid-/usr partition and you end up with an unusable system.

 if i disable selinux before one of these boots (permissive) then
 it boots up fine.

 l.


--
This message was distributed to subscribers of the selinux mailing list.
If you no longer wish to subscribe, send mail to majordomo@tycho.nsa.gov with
the words "unsubscribe selinux" without quotes as the message.

      reply	other threads:[~2004-09-09  9:46 UTC|newest]

Thread overview: 3+ messages / expand[flat|nested]  mbox.gz  Atom feed  top
2004-09-08 22:41 for bootsplash to operate correctly Luke Kenneth Casson Leighton
2004-09-09  3:01 ` Chris PeBenito
2004-09-09  9:57   ` Luke Kenneth Casson Leighton [this message]

Reply instructions:

You may reply publicly to this message via plain-text email
using any one of the following methods:

* Save the following mbox file, import it into your mail client,
  and reply-to-all from there: mbox

  Avoid top-posting and favor interleaved quoting:
  https://en.wikipedia.org/wiki/Posting_style#Interleaved_style

* Reply using the --to, --cc, and --in-reply-to
  switches of git-send-email(1):

  git send-email \
    --in-reply-to=20040909095742.GC12629@lkcl.net \
    --to=lkcl@lkcl.net \
    --cc=pebenito@gentoo.org \
    --cc=selinux@tycho.nsa.gov \
    /path/to/YOUR_REPLY

  https://kernel.org/pub/software/scm/git/docs/git-send-email.html

* If your mail client supports setting the In-Reply-To header
  via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line before the message body.
This is an external index of several public inboxes,
see mirroring instructions on how to clone and mirror
all data and code used by this external index.