All of lore.kernel.org
 help / color / mirror / Atom feed
* Switching to enforcing mode introduces new policy issues?
@ 2015-04-23 21:14 Spector, Aaron
  2015-04-23 22:19 ` Paul Moore
  2015-04-24 12:25 ` Stephen Smalley
  0 siblings, 2 replies; 17+ messages in thread
From: Spector, Aaron @ 2015-04-23 21:14 UTC (permalink / raw)
  To: SELinux (selinux@tycho.nsa.gov)

[-- Attachment #1: Type: text/plain, Size: 1324 bytes --]

Hi all,

I've been working on writing my first policy for SELinux and I've hit a bit of a snag. I've gotten the policy clean in permissive mode, but when I swap the system over to enforcing, a whole new set of policy issues crop up. Everything I've read says this isn't to be expected so I'm a bit confused as to what's happening. Output from sestatus when in permissive mode is:

SELinux status:                 enabled
SELinuxfs mount:                /sys/fs/selinux
SELinux root directory:         /etc/selinux
Loaded policy name:             default
Current mode:                   permissive
Mode from config file:          permissive
Policy MLS status:              enabled
Policy deny_unknown status:     denied
Max kernel policy version:      29

I'm running a version 26 policy and a 3.16.7 kernel.

It seems like the majority of the new deny audits are about the need for search permissions on directories between types that already have what I believe are the necessary file permissions.

So far what I've had to do to get around it is to add to my policy, but that doesn't seem like that should be necessary. If the audit is clean in permissive mode, why isn't it clean in enforcing?

Is it possible that I'm missing policy deny audits when it's in permissive mode?


Thanks,

-Aaron


[-- Attachment #2: Type: text/html, Size: 4478 bytes --]

^ permalink raw reply	[flat|nested] 17+ messages in thread

end of thread, other threads:[~2015-04-24 20:37 UTC | newest]

Thread overview: 17+ messages (download: mbox.gz follow: Atom feed
-- links below jump to the message on this page --
2015-04-23 21:14 Switching to enforcing mode introduces new policy issues? Spector, Aaron
2015-04-23 22:19 ` Paul Moore
2015-04-24  4:12   ` Spector, Aaron
2015-04-24  4:53     ` Gaurav Gangwar
2015-04-24 13:47       ` Spector, Aaron
2015-04-24 12:17     ` Miroslav Grepl
2015-04-24 12:25 ` Stephen Smalley
2015-04-24 15:18   ` Spector, Aaron
2015-04-24 15:27     ` Stephen Smalley
2015-04-24 15:57       ` Spector, Aaron
2015-04-24 16:03         ` Stephen Smalley
2015-04-24 16:05           ` Stephen Smalley
2015-04-24 16:11           ` Stephen Smalley
2015-04-24 16:30             ` Spector, Aaron
2015-04-24 16:33               ` Stephen Smalley
2015-04-24 16:36                 ` Stephen Smalley
2015-04-24 20:37                   ` Spector, Aaron

This is an external index of several public inboxes,
see mirroring instructions on how to clone and mirror
all data and code used by this external index.