Gentoo Archives: gentoo-hardened

From: Sven Vermeulen <swift@g.o>
To: gentoo-hardened@l.g.o
Subject: Re: [gentoo-hardened] Booting selinux on the bleeding edge
Date: Thu, 05 Apr 2012 15:53:30
Message-Id: 20120405155217.GC754@gentoo.org
In Reply to: [gentoo-hardened] Booting selinux on the bleeding edge by Paul de Vrieze
1 On Wed, Apr 04, 2012 at 12:12:35PM +0100, Paul de Vrieze wrote:
2 > I decided to finally take the plunge and try to see if I could get selinux
3 > on my machine. There were some easy problems to fix (like selinux-cups not
4 > depending on selinux-lpd) but it seems that latest openrc with latest udev
5 > and latest kernel don't really like eachother. I get quite some errors at
6 > boot as well as misslabeled dynamic files (/run and /dev are misslabeled).
7 > I've attached the errors and the output of relabeling /dev
8
9 As I see kdevtmpfs in the logs, I assume you have CONFIG_DEVTMPFS set?
10 I know it wasn't supported a while ago, because the kernel isn't
11 SELinux-aware (in the sense that it calls libselinux to set file contexts
12 and such). There was some talk about udev detecting the creates and
13 (re)setting the contexts through udev, but that caused issued with libvirt.
14
15 I'm not sure about the current state about it though...
16
17 Wkr,
18 Sven Vermeulen

Replies

Subject Author
Re: [gentoo-hardened] Booting selinux on the bleeding edge Paul de Vrieze <pauldv@g.o>