All of lore.kernel.org
 help / color / mirror / Atom feed
From: Daniel J Walsh <dwalsh@redhat.com>
To: "Osborn, Justin D." <Justin.Osborn@jhuapl.edu>
Cc: selinux@tycho.nsa.gov
Subject: Re: init unconfined in RHEL4?
Date: Tue, 03 Oct 2006 17:01:59 -0400	[thread overview]
Message-ID: <4522CFC7.7040801@redhat.com> (raw)
In-Reply-To: <7B95239DDD54E54B9BFA23847142B1EE10A29E@aplesnation.dom1.jhuapl.edu>

Osborn, Justin D. wrote:
>
> I'm working on a RHEL4 system with the Reference Policy and init is 
> running in unconfined_t.  This leads to most other processes on the 
> system running in unconfined_t.  Has anyone seen similar errors?
>
In RHEL4 only 15 Targets are confined,  Everything else runs in an 
unconfined domain.
>
> This is the Ref. Policy version released in March, I got the latest 
> svn version but it doesn't work with the libsepol and checkpolicy 
> RHEL4 RPMs on the Tresys site.
>
> I'm also having a strange error where I get denied messages saying 
> something was trying to access a file with context unlabeled_t when 
> `ls -Z` shows the file is clearly labeled something else.
>
ls -Z is reading the label on the file.  While the other domains are 
getting it from the kernel.  Probably the type of the file is no longer 
defined in policy, so the kernel says it is unlabled_t.  You should 
execute  restorecon on it to clean it up.

>
> Has anyone seen similar things on RHEL4?
>
> Thanks,
> Justin
>
> P.S. I managed to get my template working, many thanks to Dave Caplan.
>
> -----Original Message-----
> From: Osborn, Justin D.
> Sent: Mon 9/25/2006 10:09 AM
> To: selinux@tycho.nsa.gov
> Subject: Errors with runcon - RHEL4/refpolicy
>
> Hi everybody,
>       I'm working on a project to do containment of VMware VMs using 
> SELinux policy.  Our system is set up on RHEL4 and I have the 
> Reference Policy installed. 
>
>       We're trying to reuse the VMware policy that was originally 
> distributed with the Reference Policy.  Specifically there is a 
> per-user-domain template that we modified for our use and instantiate 
> from another te file.  The policy compiles and our VMs are properly 
> labeled after relabeling.
>
>      The problem is that when I try to kick off a VM using runcon, I 
> get the non-descript "unable to setup security context" error.  The 
> command I'm running is: runcon root:system_r:ziplock_vm1_vmware_t 
> vmware-cmd start /VMs/foo.vmx.  My bash shell is running as 
> root:system_r:unconfined_t.  I added my types to system_r and verified 
> with apol.
>
>      So my questions are:
>      a) Why was the VMware policy renoved from the Reference Policy?
>      b) What am I missing with the runcon error?  Is there somewhere I 
> can look for a more descriptive error message?
>
> Thanks,
> Justin
> JHU/APL
>
>
>
>
>
>
>


--
This message was distributed to subscribers of the selinux mailing list.
If you no longer wish to subscribe, send mail to majordomo@tycho.nsa.gov with
the words "unsubscribe selinux" without quotes as the message.

  reply	other threads:[~2006-10-03 21:01 UTC|newest]

Thread overview: 7+ messages / expand[flat|nested]  mbox.gz  Atom feed  top
2006-09-25 14:09 Errors with runcon - RHEL4/refpolicy Osborn, Justin D.
2006-09-25 19:39 ` Christopher J. PeBenito
2006-10-02 21:07 ` init unconfined in RHEL4? Osborn, Justin D.
2006-10-03 21:01   ` Daniel J Walsh [this message]
2006-10-03 21:54     ` Russell Coker
2006-10-04 13:15       ` Christopher J. PeBenito
  -- strict thread matches above, loose matches on Subject: below --
2006-10-04 11:45 Osborn, Justin D.

Reply instructions:

You may reply publicly to this message via plain-text email
using any one of the following methods:

* Save the following mbox file, import it into your mail client,
  and reply-to-all from there: mbox

  Avoid top-posting and favor interleaved quoting:
  https://en.wikipedia.org/wiki/Posting_style#Interleaved_style

* Reply using the --to, --cc, and --in-reply-to
  switches of git-send-email(1):

  git send-email \
    --in-reply-to=4522CFC7.7040801@redhat.com \
    --to=dwalsh@redhat.com \
    --cc=Justin.Osborn@jhuapl.edu \
    --cc=selinux@tycho.nsa.gov \
    /path/to/YOUR_REPLY

  https://kernel.org/pub/software/scm/git/docs/git-send-email.html

* If your mail client supports setting the In-Reply-To header
  via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line before the message body.
This is an external index of several public inboxes,
see mirroring instructions on how to clone and mirror
all data and code used by this external index.