All of lore.kernel.org
 help / color / mirror / Atom feed
From: Karl MacMillan <kmacmillan@mentalrootkit.com>
To: Catalin DIMA <dima@univ-paris12.fr>
Cc: selinux@tycho.nsa.gov
Subject: Re: Problems installing current version of refpolicy with FC6
Date: Mon, 29 Jan 2007 14:49:26 -0500	[thread overview]
Message-ID: <45BE4FC6.4090502@mentalrootkit.com> (raw)
In-Reply-To: <45BE44FC.8080303@univ-paris12.fr>

Catalin DIMA wrote:
> I am trying to install different versions of refpolicy on Dell X1 
> machines with FC6, for teaching purposes, but no choice of build.conf 
> parameters can make it.

Just to check - are you certain that you want the full policy? You may 
be able to do the teaching you need with policy modules only.

  I get outcomes from "kernel panic" (when trying
> to install the "strict monolithic" version of refpolicy) to system stall 
> (when trying to install "targeted monolithic" version), or outputs like 
> below (when trying to install "targeted modular" version -- this 
> installation ends in stack problems which also cause system halt). Every 
> time the kernel does not panic, there's a whole list of booleans that 
> are unknown to libsepol.load_booleans, though generated from refpolicy 
> via the "install" target of the Makefile.
> 

Did you enable mcs? The standard FC6 policy is targeted-mcs and the 
presence of the mcs components in the file system labels may be the 
cause of your problems.

> I have tried on two different laptops but the outcome is the same. I 
> have also tried with the latest or older versions and the output is the 
> same. Did anyone observe similar behaviors with laptops/FC6/refpolicy ?...
> 
> Output :
> libsepol.load_booleans: unknown boolean user_ttyfile_stat (and others)

The unknown boolean messages should be harmless I believe.

You can extract the build.conf from the policy source rpm as well, which 
is likely a good starting point.

Karl

--
This message was distributed to subscribers of the selinux mailing list.
If you no longer wish to subscribe, send mail to majordomo@tycho.nsa.gov with
the words "unsubscribe selinux" without quotes as the message.

  reply	other threads:[~2007-01-29 19:48 UTC|newest]

Thread overview: 10+ messages / expand[flat|nested]  mbox.gz  Atom feed  top
2007-01-29 19:03 Problems installing current version of refpolicy with FC6 Catalin DIMA
2007-01-29 19:49 ` Karl MacMillan [this message]
2007-01-29 21:08   ` Catalin DIMA
2007-01-29 21:35     ` Karl MacMillan
2007-01-29 23:24       ` Catalin DIMA
2007-01-30 14:52         ` Karl MacMillan
2007-02-02 16:15           ` DWARF2 [was : Problems installing refpolicy with FC6] Catalin DIMA
2007-02-02 17:02             ` Paul Moore
2007-02-02 17:29               ` Catalin DIMA
2007-02-05 15:34     ` Problems installing current version of refpolicy with FC6 Stephen Smalley

Reply instructions:

You may reply publicly to this message via plain-text email
using any one of the following methods:

* Save the following mbox file, import it into your mail client,
  and reply-to-all from there: mbox

  Avoid top-posting and favor interleaved quoting:
  https://en.wikipedia.org/wiki/Posting_style#Interleaved_style

* Reply using the --to, --cc, and --in-reply-to
  switches of git-send-email(1):

  git send-email \
    --in-reply-to=45BE4FC6.4090502@mentalrootkit.com \
    --to=kmacmillan@mentalrootkit.com \
    --cc=dima@univ-paris12.fr \
    --cc=selinux@tycho.nsa.gov \
    /path/to/YOUR_REPLY

  https://kernel.org/pub/software/scm/git/docs/git-send-email.html

* If your mail client supports setting the In-Reply-To header
  via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line before the message body.
This is an external index of several public inboxes,
see mirroring instructions on how to clone and mirror
all data and code used by this external index.