Gentoo Archives: gentoo-hardened

From: Joshua Brindle <method@g.o>
To: nixnut <nixnut@×××××.nl>
Cc: gentoo-hardened@l.g.o
Subject: Re: [gentoo-hardened] selinux + pty problem
Date: Sat, 10 Apr 2004 11:25:04
Message-Id: 4077D987.9000803@gentoo.org
In Reply to: [gentoo-hardened] selinux + pty problem by nixnut
1 Per the instructions for selinux use devpts and a standard (non devfs) /dev
2
3 see
4 http://www.gentoo.org/proj/en/hardened/selinux/selinux-x86-install.xml#doc_chap15
5 for the fstab entries required by selinux
6
7 Joshua Brindle
8
9 nixnut wrote:
10
11 > G'day all,
12 >
13 > I'm having some problems with selinux and devfs. selinux does not support devfs but without devfs normal users
14 > can't start xterms.
15 >
16 > I've tried a number of kernels (all 2.6.4-hardened-r3) with different configurations.
17 > All kernels without devfs result in the pty problem:
18 > xterm: Error 32, errno 2: No such file or directory
19 > Reason: get_pty: not enough ptys
20 >
21 > selinux enabled kernels with devfs result in a large number of "avc: denied .." messages. If I understand correctly
22 > the dynamically created devices can't be labelled properly.
23 >
24 > The solution for non-selinux systems is obviously enabling devfs (as mentioned in a number of threads on
25 > forums.gentoo), but for selinux creates the other problem.
26 > Any ideas on how to have both selinux and the usual use of pty's?
27 >
28 > regards,
29 > nixnut
30 >
31 > www.lycosmail.nl - Gratis 15 MB mailbox - Nu ook hotmail via Lycos Mail!
32 >
33 >
34 >
35 >
36 >
37 > ------------------------------------------------------------------------
38 >
39 > --
40 > gentoo-hardened@g.o mailing list
41
42
43 --
44 gentoo-hardened@g.o mailing list

Replies

Subject Author
Re: [gentoo-hardened] selinux + pty problem Chris PeBenito <pebenito@g.o>