All of lore.kernel.org
 help / color / mirror / Atom feed
From: "Justin P. Mattock" <justinmattock@gmail.com>
To: selinux@tycho.nsa.gov
Subject: Re: Selinux in enforcing mode prevent network interface to be configured at boot for Debian stable ( 5.0)
Date: Sun, 07 Feb 2010 09:24:25 -0800	[thread overview]
Message-ID: <4B6EF749.8070503@gmail.com> (raw)
In-Reply-To: <20100207162358.GR1750@myhost.felk.cvut.cz>

On 02/07/10 08:23, Michal Svoboda wrote:
> Justin P. Mattock wrote:
>> if nothing the do a
>> sudo /usr/sbin/semodule -DB
>> (reboot)
>> then what does audit2allow say?
>> should give you some allow rules
>> if so add them to your policy.
>
> This will most likely output a very large number of rules that don't
> make sense, ie. they would do more bad than good.
>

  true.. well if there's a better idea to help this person out,
then please add..(I figured the most simplest way to do so
without having to do brain surgery).

> The basic problem is that the network scripts don't have their own
> restricted domain in which they could run. Running them from udev on
> 'network hotplug event' will copy the udev context, which doesn't have
> enough privileges to configure network. Giving these privileges to udev
> directly would be sub-optimal.
>
> Michal Svoboda

in this case if this is ifup, then it should be a no brainer(but could 
be wrong).

Justin P. Mattock

--
This message was distributed to subscribers of the selinux mailing list.
If you no longer wish to subscribe, send mail to majordomo@tycho.nsa.gov with
the words "unsubscribe selinux" without quotes as the message.

  reply	other threads:[~2010-02-07 17:22 UTC|newest]

Thread overview: 8+ messages / expand[flat|nested]  mbox.gz  Atom feed  top
2010-02-07  8:12 Selinux in enforcing mode prevent network interface to be configured at boot for Debian stable ( 5.0) Elko Kuric
2010-02-07  8:42 ` Justin P. Mattock
2010-02-07  9:31   ` Elko Kuric
2010-02-07  9:59     ` Justin P. Mattock
2010-02-07 16:23       ` Michal Svoboda
2010-02-07 17:24         ` Justin P. Mattock [this message]
2010-02-07 16:16 ` Michal Svoboda
2010-02-08  9:32   ` Elko Kuric

Reply instructions:

You may reply publicly to this message via plain-text email
using any one of the following methods:

* Save the following mbox file, import it into your mail client,
  and reply-to-all from there: mbox

  Avoid top-posting and favor interleaved quoting:
  https://en.wikipedia.org/wiki/Posting_style#Interleaved_style

* Reply using the --to, --cc, and --in-reply-to
  switches of git-send-email(1):

  git send-email \
    --in-reply-to=4B6EF749.8070503@gmail.com \
    --to=justinmattock@gmail.com \
    --cc=selinux@tycho.nsa.gov \
    /path/to/YOUR_REPLY

  https://kernel.org/pub/software/scm/git/docs/git-send-email.html

* If your mail client supports setting the In-Reply-To header
  via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line before the message body.
This is an external index of several public inboxes,
see mirroring instructions on how to clone and mirror
all data and code used by this external index.