From: Rogelio Serrano <rogelio@smsglobal.net>
To: selinux@tycho.nsa.gov
Subject: Re: booting in enforcing mode
Date: Sun, 11 Apr 2004 01:28:01 +0800 [thread overview]
Message-ID: <f2d9139e96f439881364be08a8525159@debian> (raw)
In-Reply-To: <edb0cd3759adb044522304e91946929a@debian>
On 2004-04-10 22:53:17 +0800 Rogelio Serrano
<rogelio@smsglobal.net> wrote:
> On 2004-04-10 22:22:59 +0800 Russell Coker
> <russell@coker.com.au> wrote:
>
>> On Sat, 10 Apr 2004 17:10, Rogelio Serrano
>> <rogelio@smsglobal.net> wrote:
>>> I can boot in enforcing mode now but there seem to be too
>>> many
>>> denials in my log. Which denials can be considered harmless?
>>> i
>>> can see a lot of ioctl, sys_tty_config and getattr.
>>
>> Show us a sample of the messages.
>>
>> When determining whether the denials are harmless it's
>> usually a matter of
>> the scontext and tcontext.
>>
>> As for sys_tty_config, in the transition to kernel 2.6.x the
>> handling of
>> this changed and lots of applications need it. I've
>> considered having the
>> daemon_base_domain() macro allow or dontaudit it. Most
>> applications that
>> request it don't seem to really need it (they work fine
>> without it).
>>
>
> I see. I think i have to remove some of those that i added.
> the hotplug
> scripts are the noisiest. i will fix /bin/login first. its the
> login fom
> util-linux 2.12 and im not using PAM. i need to label the tty
> properly. i can
> login but not into /User/Admin. login drops me into / then i
> can just "cd"
> and im in sysadm_home_dir. all home directories are in /Users
> and admins home
> dir is /Users/Admin alongside the other users. The context for
> /Users is
> system_u:object_r:file_t. Is that ok? Shouldnt it be root_t?
> Or should i
> create a totally new type.
>
>
>
> --
> This message was distributed to subscribers of the selinux
> mailing list.
> If you no longer wish to subscribe, send mail to
> majordomo@tycho.nsa.gov with
> the words "unsubscribe selinux" without quotes as the message.
>
^[The problem was fixed by setting /Users to
system_u:object_r:home_root_t.
The denials are all harmless. Im rebuilding the system from
scratch in enforcing mode now. This will be a good test of the
policy. I rewrote mount, syslogd, and klogd to have the bare
minimum priviledges. Im going to rewrite init next. im looking
for a bash replacement its incredibly noisy. maybe its time to
stop using boot scripts.
--
This message was distributed to subscribers of the selinux mailing list.
If you no longer wish to subscribe, send mail to majordomo@tycho.nsa.gov with
the words "unsubscribe selinux" without quotes as the message.
next prev parent reply other threads:[~2004-04-10 17:28 UTC|newest]
Thread overview: 12+ messages / expand[flat|nested] mbox.gz Atom feed top
2004-04-10 7:10 booting in enforcing mode Rogelio Serrano
2004-04-10 14:22 ` Russell Coker
2004-04-10 14:53 ` Rogelio Serrano
2004-04-10 17:28 ` Rogelio Serrano [this message]
2004-04-11 10:23 ` Russell Coker
2004-04-11 13:35 ` Rogelio Serrano
2004-04-12 6:37 ` Russell Coker
2004-04-12 7:10 ` Rogelio Serrano
2004-04-12 10:29 ` Russell Coker
2004-04-11 10:23 ` Russell Coker
2004-04-11 13:41 ` Rogelio Serrano
2004-04-11 14:41 ` Rogelio Serrano
Reply instructions:
You may reply publicly to this message via plain-text email
using any one of the following methods:
* Save the following mbox file, import it into your mail client,
and reply-to-all from there: mbox
Avoid top-posting and favor interleaved quoting:
https://en.wikipedia.org/wiki/Posting_style#Interleaved_style
* Reply using the --to, --cc, and --in-reply-to
switches of git-send-email(1):
git send-email \
--in-reply-to=f2d9139e96f439881364be08a8525159@debian \
--to=rogelio@smsglobal.net \
--cc=selinux@tycho.nsa.gov \
/path/to/YOUR_REPLY
https://kernel.org/pub/software/scm/git/docs/git-send-email.html
* If your mail client supports setting the In-Reply-To header
via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line
before the message body.
This is an external index of several public inboxes,
see mirroring instructions on how to clone and mirror
all data and code used by this external index.