All of lore.kernel.org
 help / color / mirror / Atom feed
* [refpolicy] Why console not usable by default?
@ 2010-10-26  9:58 TaurusHarry
  2010-10-26 11:23 ` Dominick Grift
  2010-10-26 12:03 ` Christopher J. PeBenito
  0 siblings, 2 replies; 6+ messages in thread
From: TaurusHarry @ 2010-10-26  9:58 UTC (permalink / raw)
  To: refpolicy


Hi refpolicy experts,

I am trying to play with the refpolicy from the latest git tree in a qemu environment, which I could login from serial console or by ssh. I run into a serial of problem when logging in from the serial console nor running userspace applications on top of it. The attached is the patch I made up so far to make the serial console "usable" by normal operations.

I couldn't help wondering why the console is not made available for many userspace domains in the refpolicy by default? Take the getty_t for instance, in getty.te, not only the getty_t not permitted to use console, but further more, a dontaudit rule is used to suppress the related AVC Denied messages:

-term_dontaudit_use_console(getty_t)
+term_use_console(getty_t)

I guess I would have to make above changes in order to login from the console, otherwise the mingetty will fail with following error messages:
        INIT: Id "0" respawning too fast: disabled for 5 minutes
        INIT: no more processes left in this runlevel

Furthermore, if we remove the "term_dontaudit_use_console(getty_t)" rule, we can see that /sbin/mingetty fails to execute /bin/login:
        type=1400 audit(1264520547.936:68): avc:  denied  { noatsecure } for  pid=2292 comm="login" scontext=system_u:system_r:getty_t:s0-s15:c0.c255 tcontext=system_u:system_r:local_login_t:s0-s15:c0.c255 tclass=process


Could some one enlighten me on the decision made about the console in the refpolicy implementation? and why?

Thank you very much!

Best regards,
Harry
 		 	   		  
-------------- next part --------------
An HTML attachment was scrubbed...
URL: http://oss.tresys.com/pipermail/refpolicy/attachments/20101026/824f6c31/attachment.html 
-------------- next part --------------
A non-text attachment was scrubbed...
Name: making-the-console-usable.patch
Type: text/x-patch
Size: 2737 bytes
Desc: not available
Url : http://oss.tresys.com/pipermail/refpolicy/attachments/20101026/824f6c31/attachment.bin 

^ permalink raw reply	[flat|nested] 6+ messages in thread

end of thread, other threads:[~2010-10-27 12:22 UTC | newest]

Thread overview: 6+ messages (download: mbox.gz follow: Atom feed
-- links below jump to the message on this page --
2010-10-26  9:58 [refpolicy] Why console not usable by default? TaurusHarry
2010-10-26 11:23 ` Dominick Grift
2010-10-26 12:03 ` Christopher J. PeBenito
2010-10-26 12:27   ` Daniel J Walsh
2010-10-27  9:11     ` TaurusHarry
2010-10-27 12:22     ` Christopher J. PeBenito

This is an external index of several public inboxes,
see mirroring instructions on how to clone and mirror
all data and code used by this external index.