Gentoo Archives: gentoo-hardened

From: Vladimir Berezniker <vmpn@×××××××××.com>
To: gentoo-hardened@l.g.o
Subject: Re: [gentoo-hardened] [SELinux] broken policy and emerge filelabeling
Date: Fri, 17 Sep 2004 01:00:26
Message-Id: 35125.216.254.64.115.1095382815.squirrel@remote.vmpn.net
In Reply to: Re: [gentoo-hardened] [SELinux] broken policy and emerge file labeling by Chris PeBenito
1 <quote who="Chris PeBenito">
2 > On Thu, 2004-09-16 at 17:03, Vladimir Berezniker wrote:
3 >> I am unable to load a policy into the running kernel:
4 >>
5 >> * Loading policy.17
6 >> /usr/sbin/load_policy: security_load_policy failed
7 >> make: *** [tmp/load] Error 3
8 >>
9 >> My kernel is 2.6.7-gentoo-r11. I cannot find the cause of why this is
10 >> happening so I wanted to upgrade the kernel.
11 >>
12 >> However I get:
13 >>
14 >> >>> Setting SELinux security labels
15 >> /usr/sbin/setfiles: invalid context system_u:object_r:file_context_t on
16 >> line number 259
17 >> /usr/sbin/setfiles: read 702 specifications
18 >
19 > As previously stated, you need to reboot.
20 >
21 > http://marc.theaimsgroup.com/?l=gentoo-hardened&m=109448600406599&w=2
22 >
23 > --
24 > Chris PeBenito
25 > <pebenito@g.o>
26 > Developer,
27 > Hardened Gentoo Linux
28 > Embedded Gentoo Linux
29 >
30 > Public Key: http://pgp.mit.edu:11371/pks/lookup?op=get&search=0xE6AF9243
31 > Key fingerprint = B0E6 877A 883F A57A 8E6A CB00 BC8E E42D E6AF 9243
32 >
33 Thank you very much. Reboot did in fact fix this.
34
35 However, I am still curious about asking emerge not to label files. The reason
36 I ask is that once before, I managed to messup /etc/security/selinux. I could
37 not get a policy to compile. I tried remerging base-policy, however it would
38 not work due to labeling step failing. So I was curious if there was a way to
39 ask emerge to skip the labeling step.
40
41 Sincerely,
42 Vladimir Berezniker
43
44
45
46
47
48 --
49 gentoo-hardened@g.o mailing list

Replies

Subject Author
Re: [gentoo-hardened] [SELinux] broken policy and emerge filelabeling Chris PeBenito <pebenito@g.o>