public inbox for linux-kernel@vger.kernel.org
 help / color / mirror / Atom feed
* 2.6.7-rc2: open() hangs on ReiserFS with SELinux enabled
@ 2004-06-02 17:48 Dmitry Baryshkov
  2004-06-02 18:40 ` Stephen Smalley
  2004-06-02 18:48 ` Valdis.Kletnieks
  0 siblings, 2 replies; 7+ messages in thread
From: Dmitry Baryshkov @ 2004-06-02 17:48 UTC (permalink / raw)
  To: linux-kernel

Hello,

I tried enabling SELinux on my Linux-box, using ReiserFS as /, kernel
2.6.7-rc2.

After relabeling and rebooting in non-enforcing mode everything worked
well, exept the fact, that new files on reiserfs filesystems don't get
security attributes.

So I added 'fs_use_xattr reiserfs system_u:object_r:fs_t;' to the policy,
rebooted and found, that mount hangs during opening of /etc/mtab~<pid>
(even in non-enforcing mode).

If I remove that line from SELinux policy, systems boots up OK.

Here are last lines from #strace mount / -o remount :

=== Cut ===
open("/etc/mtab~202", O_WRONLY|O_CREAT|O_LARGEFILE, 0600audit(1085949484.378:0): avc:  denied  { write } for  pid=202 exe=/bin/mount name=etc dev=hda5 ino=91 scontext=system_u:system_r:kernel_t tcontext=system_u:object_r:etc_t tclass=dir
audit(1085949484.378:0): avc:  denied  { add_name } for  pid=202 exe=/bin/mount name=etc dev=hda5 ino=91 scontext=system_u:system_r:kernel_t tcontext=system_u:object_r:etc_t tclass=dir
audit(1085949484.378:0): avc:  denied  { create } for  pid=202 exe=/bin/mount name=mtab~202 dev=hda5 ino=91 scontext=system_u:system_r:kernel_t tcontext=system_u:object_r:etc_t tclass=file
=== Cut ===

Tell me, if I need to provide any additional info.

-- 
With best wishes
Dmitry Baryshkov

^ permalink raw reply	[flat|nested] 7+ messages in thread

end of thread, other threads:[~2004-06-04 12:00 UTC | newest]

Thread overview: 7+ messages (download: mbox.gz follow: Atom feed
-- links below jump to the message on this page --
2004-06-02 17:48 2.6.7-rc2: open() hangs on ReiserFS with SELinux enabled Dmitry Baryshkov
2004-06-02 18:40 ` Stephen Smalley
2004-06-03  8:36   ` Dmitry Baryshkov
2004-06-03 14:09     ` Stephen Smalley
2004-06-03 19:46       ` Stephen Smalley
2004-06-04 12:00         ` Dmitry Baryshkov
2004-06-02 18:48 ` Valdis.Kletnieks

This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox