From: Dennis Wronka <linuxweb@gmx.net>
To: Stephen Smalley <sds@tycho.nsa.gov>, SELinux@tycho.nsa.gov
Subject: Re: Policy loading problem
Date: Wed, 20 May 2009 21:46:50 +0800 [thread overview]
Message-ID: <200905202146.54559.linuxweb@gmx.net> (raw)
In-Reply-To: <1242820009.20082.374.camel@localhost.localdomain>
[-- Attachment #1: Type: text/plain, Size: 2032 bytes --]
I have actually tried both.
The way it's usually done is through a patched init, which used to work some
time ago (I don't remember which version of the kernel, the policy and the
SELinux-tools/-libraries I used then, as everything always is being updated
and I worked on a lot of other stuff in between).
I also tried the approach Fedora uses, pretty much taking apart their initrd
and reimplementing the load_policy-command from nash into a seperate program
as I had trouble compiling nash). I got it partially working later, but not in
the way I used to do it and not the way it's supposed to be.
So, as said, the it's supposed to be is a patched init, although I could live
with doing it in my initramfs (I use that instead of an initrd, but it's
basically the same anyway).
Still I find it quite confusing that the policy gets loaded when I set SELinux
to enforcing, but not when I set it to permissive.
On Wednesday 20 May 2009 19:46:49 you wrote:
> On Wed, 2009-05-20 at 09:21 +0200, Dennis Wronka wrote:
> > Hello folks,
> >
> > currently I am experiencing quite a strange problem during system-boot.
> > The problem is that the policy only gets loaded when I boot into
> > enforcing-mode. Booting into permissive mode (doesn't matter if via
> > kernel-parameter or config-file) does not load the policy at all.
> >
> > I am using Kernel 2.6.29.3 and Reference Policy 2.20081210.
> > Did anything change in the latest kernel or policy that triggers this? Is
> > it possible to create a policy that cannot be loaded in permissive mode?
> >
> > Any help or suggestion would be great.
>
> What mechanism are you using to perform the initial policy load (Fedora
> originally patched /sbin/init then migrated to performing the load from
> the initrd; Ubuntu does the load from initrd but in a different manner;
> Debian still uses a patched init I believe)?
>
> Can you post the logic for your initial policy load, whether it is a
> patch to /sbin/init or an initrd script?
[-- Attachment #2: This is a digitally signed message part. --]
[-- Type: application/pgp-signature, Size: 198 bytes --]
next prev parent reply other threads:[~2009-05-20 13:46 UTC|newest]
Thread overview: 26+ messages / expand[flat|nested] mbox.gz Atom feed top
2009-05-18 10:19 avc: denied null Dominick Grift
2009-05-18 12:50 ` Stephen Smalley
2009-05-18 12:59 ` Dominick Grift
2009-05-18 18:52 ` Eamon Walsh
2009-05-20 3:11 ` Eamon Walsh
2009-05-20 7:21 ` Policy loading problem Dennis Wronka
2009-05-20 11:46 ` Stephen Smalley
2009-05-20 13:46 ` Dennis Wronka [this message]
2009-05-20 13:49 ` Stephen Smalley
2009-05-20 14:07 ` Dennis Wronka
2009-05-20 14:09 ` Stephen Smalley
2009-05-20 14:21 ` Stephen Smalley
2009-05-20 14:42 ` Dennis Wronka
2009-05-20 14:40 ` Stephen Smalley
2009-05-20 14:57 ` Dennis Wronka
2009-05-20 14:59 ` Stephen Smalley
2009-05-20 15:22 ` Dennis Wronka
2009-05-20 15:44 ` Dennis Wronka
2009-05-20 16:44 ` Stephen Smalley
2009-05-20 21:01 ` Paul Howarth
2009-05-20 15:10 ` Stephen Smalley
2009-07-07 15:53 ` Joshua Brindle
2009-05-20 11:08 ` avc: denied null Dominick Grift
2009-05-21 2:36 ` Eamon Walsh
2009-05-21 12:19 ` Dominick Grift
2009-05-21 20:15 ` Dominick Grift
Reply instructions:
You may reply publicly to this message via plain-text email
using any one of the following methods:
* Save the following mbox file, import it into your mail client,
and reply-to-all from there: mbox
Avoid top-posting and favor interleaved quoting:
https://en.wikipedia.org/wiki/Posting_style#Interleaved_style
* Reply using the --to, --cc, and --in-reply-to
switches of git-send-email(1):
git send-email \
--in-reply-to=200905202146.54559.linuxweb@gmx.net \
--to=linuxweb@gmx.net \
--cc=SELinux@tycho.nsa.gov \
--cc=sds@tycho.nsa.gov \
/path/to/YOUR_REPLY
https://kernel.org/pub/software/scm/git/docs/git-send-email.html
* If your mail client supports setting the In-Reply-To header
via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line
before the message body.
This is an external index of several public inboxes,
see mirroring instructions on how to clone and mirror
all data and code used by this external index.