From: Gene Heskett <gene.heskett@gmail.com>
To: "Rafael J. Wysocki" <rjw@sisk.pl>
Cc: James Morris <jmorris@namei.org>,
linux-kernel@vger.kernel.org, Eric Paris <eparis@redhat.com>,
Stephen Smalley <sds@tycho.nsa.gov>
Subject: Re: 2.6.27-rc1: strange fstab issue (Re: 2.6.27-rc1 + selinux new options = no httpd)
Date: Fri, 1 Aug 2008 09:39:04 -0400 [thread overview]
Message-ID: <200808010939.04186.gene.heskett@gmail.com> (raw)
In-Reply-To: <200808010017.28125.rjw@sisk.pl>
On Thursday 31 July 2008, Rafael J. Wysocki wrote:
Update by Gene below.
>On Thursday, 31 of July 2008, James Morris wrote:
>> On Thu, 31 Jul 2008, Gene Heskett wrote:
>> > >Which new options?
>> >
>> > Make xconfig-->security options:
>> >
>> > XFRM Networking security hooks
>> >
>> > and several others just below it. Unforch, I can't copy/paste the
>> > screen.
>>
>> I can't really imagine what that is (although if you enable the secmark
>> controls under the main SELinux menu, which are disabled by default,
>> there could be problems).
>
>On a possibly related note, I've been observing a strange issue on one of
>my test boxes with OpenSUSE 10.3 recently. Namely, the fsck complains
>that there's no passno value in the fstab, although it obviously is present.
>
>Strangely enough, if the kernel is compiled with CONFIG_SECURITY_SELINUX
> unset, the fsck doesn't complain about the missing passno field any more.
>
>Thanks,
>Rafael
I just did a 2.6.27-rc1 rebuild on a pure, all defaults 'make oldconfig' from
my 2.6.26 final .config moved to that src tree.
httpd is still being denied access to its log files and dies during the bootup.
This is a showstopper for me.
>From the log:
Aug 1 09:12:13 coyote setroubleshoot: SELinux prevented httpd reading and writing access to http files. For complete
SELinux messages. run sealert -l ecd4e1d6-59fa-47ff-830d-3fb7d9114805
>From the output of that report:
The following command will allow this access:
setsebool -P httpd_unified=1
(Gene: but it is not effective)
Additional Information:
Source Context system_u:system_r:httpd_t:s0
Target Context system_u:object_r:httpd_log_t:s0
Target Objects ./error_log [ file ]
Source httpd
Source Path /usr/sbin/httpd
Port <Unknown>
Host coyote.coyote.den
Source RPM Packages httpd-2.2.8-1.fc8
Target RPM Packages
Policy RPM selinux-policy-3.0.8-109.fc8
Selinux Enabled True
Policy Type targeted
MLS Enabled True
Enforcing Mode Enforcing
Plugin Name httpd_unified
Host Name coyote.coyote.den
Platform Linux coyote.coyote.den 2.6.27-rc1 #2 PREEMPT Wed
Jul 30 19:05:14 EDT 2008 i686 athlon
Alert Count 11
First Seen Tue Jul 29 15:51:41 2008
There is more but you've seen it previously I believe.
Thanks for any help/solution.
--
Cheers, Gene
"There are four boxes to be used in defense of liberty:
soap, ballot, jury, and ammo. Please use in that order."
-Ed Howdershelt (Author)
Advertising may be described as the science of arresting the human
intelligence long enough to get money from it.
next prev parent reply other threads:[~2008-08-01 13:39 UTC|newest]
Thread overview: 15+ messages / expand[flat|nested] mbox.gz Atom feed top
2008-07-31 2:54 2.6.27-rc1 + selinux new options = no httpd Gene Heskett
2008-07-31 3:36 ` Valdis.Kletnieks
2008-07-31 4:43 ` James Morris
2008-07-31 13:09 ` Gene Heskett
2008-07-31 14:44 ` Eric Paris
2008-07-31 17:47 ` Stephen Smalley
2008-08-01 18:52 ` Gene Heskett
2008-08-01 12:51 ` Stephen Smalley
2008-08-01 14:47 ` Al Viro
2008-07-31 20:02 ` James Morris
2008-07-31 22:17 ` 2.6.27-rc1: strange fstab issue (Re: 2.6.27-rc1 + selinux new options = no httpd) Rafael J. Wysocki
2008-08-01 13:39 ` Gene Heskett [this message]
2008-08-01 13:47 ` Eric Paris
2008-08-01 14:02 ` Al Viro
2008-08-01 14:13 ` Gene Heskett
Reply instructions:
You may reply publicly to this message via plain-text email
using any one of the following methods:
* Save the following mbox file, import it into your mail client,
and reply-to-all from there: mbox
Avoid top-posting and favor interleaved quoting:
https://en.wikipedia.org/wiki/Posting_style#Interleaved_style
* Reply using the --to, --cc, and --in-reply-to
switches of git-send-email(1):
git send-email \
--in-reply-to=200808010939.04186.gene.heskett@gmail.com \
--to=gene.heskett@gmail.com \
--cc=eparis@redhat.com \
--cc=jmorris@namei.org \
--cc=linux-kernel@vger.kernel.org \
--cc=rjw@sisk.pl \
--cc=sds@tycho.nsa.gov \
/path/to/YOUR_REPLY
https://kernel.org/pub/software/scm/git/docs/git-send-email.html
* If your mail client supports setting the In-Reply-To header
via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line
before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox