From: "Justin P. mattock" <justinmattock@gmail.com>
To: Stephen Smalley <sds@tycho.nsa.gov>
Cc: Alan Rouse <alan.rouse@ericsson.com>,
"'selinux@tycho.nsa.gov'" <selinux@tycho.nsa.gov>
Subject: Re: SELinux Policy in OpenSUSE 11.2
Date: Tue, 16 Feb 2010 12:06:00 -0800 [thread overview]
Message-ID: <4B7AFAA8.6090200@gmail.com> (raw)
In-Reply-To: <1266348497.5252.123.camel@moss-pluto.epoch.ncsc.mil>
On 02/16/2010 11:28 AM, Stephen Smalley wrote:
> On Tue, 2010-02-16 at 13:04 -0500, Alan Rouse wrote:
>> Dominick, thanks for the reply. These AVC messages occur during
>> normal bootup (not from a command line), so it is the boot process
>> which is starting these in the wrong context.
>>
>> OpenSuSE 11.2 is still using System V init startup, but Fedora 12 is
>> using upstart. Perhaps that explains why the recent refpolicy is not
>> starting OpenSuse processes in the right context. Is the current
>> refpolicy known to work in System V init -based systems?
>
> Current refpolicy should still work fine for distributions using
> sysvinit. Distributions using upstart have to enable a policy
> tunable/boolean.
>
> What build.conf settings are you using? I expect that the distro_suse
> settings are obsolete, as no one has actively maintained support for
> SUSE in the upstream policy since Thomas Bleher gave up on maintaining
> SUSE SELinux packages.
>
> If you want SELinux to work with SUSE, then:
> a) you'll need to at least file bugs in their bugzilla so that they have
> some reason to believe anyone cares, and
> b) ideally you'll help track down and fix some of the problems and
> submit those fixes to them (if the fixes involve changes to system
> packages, not just policy changes) or to refpolicy as appropriate.
>
ahh.. I remember this:
http://oss.tresys.com/pipermail/refpolicy/2009-September/001447.html
from what I remember I think this had todo with some packages
not having switches turned on with SELinux support
(but if setsebool -P init_upstart=1 like you had posted
works then this has nothing todo with the packages(gnome)).
In general I came to the conclusion,
well SELinux support is there(more of an mls environment(no xserver))
And figured if I'm going to get this I probably am going to have to
re-build all of the gnome stuff(enabling the SELinux switches)which is
a pretty big job(but could be wrong).
I don't mind giving another go at this,
(or if someone else wants to dive in(have at it))
firstly I need to get some bugs taken care of
in the kernel.
Justin P. Mattock
--
This message was distributed to subscribers of the selinux mailing list.
If you no longer wish to subscribe, send mail to majordomo@tycho.nsa.gov with
the words "unsubscribe selinux" without quotes as the message.
next prev parent reply other threads:[~2010-02-16 20:06 UTC|newest]
Thread overview: 113+ messages / expand[flat|nested] mbox.gz Atom feed top
2010-02-16 14:55 SELinux Policy in OpenSUSE 11.2 Alan Rouse
2010-02-16 15:22 ` Dominick Grift
2010-02-16 18:04 ` Alan Rouse
2010-02-16 18:35 ` Dominick Grift
2010-02-16 18:52 ` Dominick Grift
2010-02-16 19:28 ` Stephen Smalley
2010-02-16 20:06 ` Justin P. mattock [this message]
2010-02-16 19:10 ` Stephen Smalley
2010-02-16 19:19 ` Alan Rouse
2010-02-16 19:38 ` Stephen Smalley
2010-02-16 21:30 ` Alan Rouse
2010-02-16 22:52 ` Dominick Grift
2010-02-17 3:36 ` Justin P. mattock
2010-02-17 7:16 ` Justin P. mattock
2010-02-17 13:43 ` Stephen Smalley
2010-02-17 15:35 ` Justin P. mattock
2010-02-17 16:34 ` Alan Rouse
2010-02-17 16:58 ` Stephen Smalley
2010-02-17 18:34 ` Alan Rouse
2010-02-17 18:50 ` Justin P. mattock
2010-02-17 18:58 ` Stephen Smalley
2010-02-17 19:39 ` Alan Rouse
2010-02-17 19:47 ` Justin P. mattock
2010-02-17 20:00 ` Stephen Smalley
2010-02-17 20:03 ` Alan Rouse
2010-02-17 20:12 ` Dominick Grift
2010-02-17 20:18 ` Stephen Smalley
2010-02-17 20:17 ` Alan Rouse
2010-02-17 20:25 ` Stephen Smalley
[not found] ` <5A5E55DF96F73844AF7DFB0F48721F0F529A7802A0@EUSAACMS0703.eamcs.ericsson.se>
[not found] ` <1266438910.4945.137.camel@moss-pluto.epoch.ncsc.mil>
2010-02-17 20:49 ` Alan Rouse
2010-02-17 21:09 ` Stephen Smalley
2010-02-17 21:11 ` Alan Rouse
2010-02-17 21:29 ` Stephen Smalley
2010-02-17 21:37 ` Stephen Smalley
2010-02-17 21:48 ` Alan Rouse
2010-02-18 14:16 ` Stephen Smalley
2010-02-18 21:28 ` Stephen Smalley
2010-02-18 16:03 ` Stephen Smalley
2010-02-18 17:36 ` Alan Rouse
2010-02-18 17:53 ` Stephen Smalley
2010-02-18 18:21 ` Alan Rouse
2010-02-19 14:49 ` Stephen Smalley
2010-02-19 15:29 ` Alan Rouse
2010-02-19 17:46 ` Stephen Smalley
2010-02-19 20:23 ` Alan Rouse
2010-02-19 21:06 ` Stephen Smalley
2010-02-19 21:10 ` Alan Rouse
[not found] ` <5A5E55DF96F73844AF7DFB0F48721F0F529A780365@EUSAACMS0703.eamcs.ericsson.se>
2010-02-18 14:12 ` Stephen Smalley
2010-02-18 14:45 ` Alan Rouse
2010-02-17 20:08 ` Alan Rouse
2010-02-18 21:40 ` Justin P. mattock
2010-02-18 21:53 ` Alan Rouse
2010-02-18 23:17 ` Justin P. mattock
2010-02-19 14:35 ` Stephen Smalley
2010-02-19 15:43 ` Justin P. mattock
2010-02-19 15:58 ` Alan Rouse
2010-02-19 16:26 ` Justin P. mattock
2010-02-19 14:28 ` Stephen Smalley
2010-02-19 15:48 ` Justin P. mattock
2010-02-19 18:46 ` Justin P. mattock
2010-02-19 21:08 ` Alan Rouse
2010-02-19 21:19 ` Dominick Grift
2010-02-19 21:22 ` Justin P. mattock
2010-02-19 21:25 ` Stephen Smalley
2010-02-19 21:30 ` Alan Rouse
2010-02-19 21:37 ` Stephen Smalley
2010-02-19 21:53 ` Alan Rouse
2010-02-22 14:10 ` Stephen Smalley
[not found] ` <5A5E55DF96F73844AF7DFB0F48721F0F52E41FF16B@EUSAACMS0703.eamcs.ericsson.se>
[not found] ` <1266850844.15933.38.camel@moss-pluto.epoch.ncsc.mil>
2010-02-22 17:39 ` Alan Rouse
2010-02-22 17:56 ` Stephen Smalley
2010-02-22 19:12 ` Alan Rouse
2010-02-22 19:37 ` Stephen Smalley
2010-02-19 23:48 ` Justin P. mattock
2010-02-22 1:29 ` Justin P. mattock
2010-02-19 21:47 ` Justin P. mattock
2010-02-22 14:00 ` Stephen Smalley
2010-02-22 19:27 ` Justin Mattock
[not found] ` <dd18b0c31002221129s4be9b56cha13b7be39c2cba36@mail.gmail.com>
2010-02-22 19:57 ` Justin P. mattock
2010-02-22 20:24 ` Stephen Smalley
2010-02-22 21:25 ` Justin Mattock
2010-02-22 21:42 ` Stephen Smalley
2010-02-22 22:10 ` Justin P. mattock
2010-02-22 22:35 ` Justin Mattock
2010-02-23 6:17 ` Justin P. mattock
2010-02-23 13:40 ` Stephen Smalley
2010-02-23 14:13 ` Justin P. mattock
2010-02-23 15:56 ` Alan Rouse
2010-02-23 16:10 ` Stephen Smalley
2010-02-23 17:41 ` Justin P. mattock
2010-02-23 18:01 ` Stephen Smalley
2010-02-23 18:30 ` Justin P. mattock
2010-02-23 18:42 ` Stephen Smalley
2010-02-23 18:58 ` Justin P. mattock
2010-02-23 19:00 ` Stephen Smalley
2010-02-23 19:03 ` Justin Mattock
2010-02-23 20:37 ` Justin P. mattock
2010-02-22 17:58 ` Alan Rouse
2010-02-22 18:23 ` Justin P. mattock
2010-02-22 18:31 ` Alan Rouse
2010-02-22 18:49 ` Justin P. mattock
[not found] ` <5A5E55DF96F73844AF7DFB0F48721F0F529A780232@EUSAACMS0703.eamcs.ericsson.se>
2010-02-17 19:58 ` Stephen Smalley
2010-02-17 20:09 ` Justin P. mattock
2010-02-17 20:21 ` Stephen Smalley
2010-02-17 23:22 ` Justin P. mattock
2010-02-18 15:17 ` Alan Rouse
2010-02-18 18:33 ` Justin P. mattock
2010-02-18 18:44 ` Alan Rouse
2010-02-17 13:35 ` Stephen Smalley
2010-02-17 15:14 ` Alan Rouse
2010-02-17 15:33 ` Stephen Smalley
-- strict thread matches above, loose matches on Subject: below --
2010-02-17 14:04 Thomas
2010-04-29 6:43 Justin P. Mattock
2010-04-29 7:01 ` Justin P. Mattock
Reply instructions:
You may reply publicly to this message via plain-text email
using any one of the following methods:
* Save the following mbox file, import it into your mail client,
and reply-to-all from there: mbox
Avoid top-posting and favor interleaved quoting:
https://en.wikipedia.org/wiki/Posting_style#Interleaved_style
* Reply using the --to, --cc, and --in-reply-to
switches of git-send-email(1):
git send-email \
--in-reply-to=4B7AFAA8.6090200@gmail.com \
--to=justinmattock@gmail.com \
--cc=alan.rouse@ericsson.com \
--cc=sds@tycho.nsa.gov \
--cc=selinux@tycho.nsa.gov \
/path/to/YOUR_REPLY
https://kernel.org/pub/software/scm/git/docs/git-send-email.html
* If your mail client supports setting the In-Reply-To header
via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line
before the message body.
This is an external index of several public inboxes,
see mirroring instructions on how to clone and mirror
all data and code used by this external index.