Gentoo Archives: gentoo-hardened

From: Robert Sharp <selinux@×××××××××××××××.org>
To: gentoo-hardened@l.g.o
Subject: Re: [gentoo-hardened] Portage-related AVCs
Date: Wed, 23 Nov 2016 17:21:23
Message-Id: 42c4b882-a64c-b3e9-0531-4b8ab1084a6d@sharp.homelinux.org
In Reply to: Re: [gentoo-hardened] Portage-related AVCs by Robert Sharp
1 On 23/11/16 16:59, Robert Sharp wrote:
2 >
3 > On 23/11/16 15:58, Jason Zaman wrote:
4 >> Either is fine, but im probably just gonna stabilize the 2.6 userspace
5 >> in a couple weeks so that one is likely easier. and setools4 is waaay
6 >> better than 3. The important point is that you dont want to have both
7 >> policy.29 and policy.30 around. Then you get weirdness like if you
8 >> downgrade a kernel or something random it'll load in the old policy
9 >> which probably doesnt work properly, so whichever you pick, make sure
10 >> you nuke the other one. and semodule -B will rebuild the whole policy
11 >> again and load it.
12 > OK - I will go with policy.30 and add the keywords etc. I did a couple
13 > of local policy changes that may not be needed so will they disappear
14 > in all of this or do I need to remove them somehow first?
15 >
16 > Thanks for all your help,
17 > Robert
18 >
19 Sorry - noticed a couple of things while preping the emerge:
20
21 1) selinux-base-policy is blocking policycoreutils so presumably I need
22 to add that to my accept_keywords?
23 2) this package has the "unconfined" use flag set but I don't use
24 unconfined. Does that matter?
25
26 Thanks again,
27 Robert

Replies

Subject Author
Re: [gentoo-hardened] Portage-related AVCs Jason Zaman <jason@×××××××××.com>