Gentoo Archives: gentoo-hardened

From: Chris PeBenito <pebenito@g.o>
To: Tad <tadglines@×××××××.net>
Cc: 'Hardened Gentoo Mail List' <gentoo-hardened@g.o>
Subject: Re: [gentoo-hardened] portage doesn't label installed files
Date: Wed, 26 Nov 2003 03:02:44
Message-Id: 1069815762.7354.3.camel@chris.pebenito.net
In Reply to: [gentoo-hardened] portage doesn't label installed files by Tad
1 On Tue, 2003-11-25 at 18:44, Tad wrote:
2 > It seems that portage will label the files in the
3 > /var/tmp/portage/<pkg>/image directory, but doesn't label the files
4 > that are installed.
5
6 It sounds like your python-selinux is missing, or broken. Try remerging
7 it. It allows portage to preserve the labels when merging it to the fs.
8
9 > Shouldn't portage wait till after the files are installed and then
10 > relabel the files?
11
12 No, that would be insecure, as there would be a short period of time
13 where the labels would be incorrect, and might even be at a lesser
14 security than they should be. Also if its a library, it would become
15 inaccessible for that period, and could break things. I don't think you
16 want that with something like glibc :)
17
18 --
19 Chris PeBenito
20 <pebenito@g.o>
21 Developer,
22 Hardened Gentoo Linux
23 Embedded Gentoo Linux
24
25 Public Key: http://pgp.mit.edu:11371/pks/lookup?op=get&search=0xE6AF9243
26 Key fingerprint = B0E6 877A 883F A57A 8E6A CB00 BC8E E42D E6AF 9243

Attachments

File name MIME type
signature.asc application/pgp-signature