Gentoo Archives: gentoo-hardened

From: Chris PeBenito <pebenito@g.o>
To: Hardened Gentoo Mail List <gentoo-hardened@l.g.o>
Subject: Re: [gentoo-hardened] SELinux updates
Date: Sun, 05 Sep 2004 14:16:04
Message-Id: 1094393771.11718.24.camel@gorn.pebenito.net
In Reply to: [gentoo-hardened] SELinux updates by Chris PeBenito
1 I have unmasked hardened-sources-2.4.27-r2,
2 hardened-dev-sources-2.6.7-r8, and selinux-base-policy-20040702 for the
3 SELinux headers update. Since my last email was a long time ago, I
4 copied the relevant portion at the bottom. The 20040702 policy is the
5 same as 20040629, except with the headers update, so if you are up to
6 date on policy, it should be a trivial policy update. The headers are
7 in the flask directory of the policy.
8
9 On Sun, 2004-06-27 at 12:07, Chris PeBenito wrote:
10 > * The 2.6.8 kernel will have some new SELinux classes for security
11 > enhanced X. The problem is that these will collide with our PaX
12 > support. This means that the kernel and the policy will have to be
13 > updated at the same time, as the kernel will not load a policy whose
14 > headers don't match its own. When 2.6.8 comes out, I will put out a
15 > policy with the new headers, and also bump all kernels that have the
16 > PaX SELinux hooks. Fortunately the PaX SELinux headers have been
17 > accepted upstream, so this won't happen again. 2.6.8 will also bring
18 > policy version 18, since fine-grained netlink socket support has been
19 > added.
20
21 If you don't reboot (with the updated kernel if relevant), you will get
22 this error:
23
24 security: the value of class pax changed
25 security: the definition of an existing class changed
26
27 The policy load will fail.
28
29 --
30 Chris PeBenito
31 <pebenito@g.o>
32 Developer,
33 Hardened Gentoo Linux
34 Embedded Gentoo Linux
35
36 Public Key: http://pgp.mit.edu:11371/pks/lookup?op=get&search=0xE6AF9243
37 Key fingerprint = B0E6 877A 883F A57A 8E6A CB00 BC8E E42D E6AF 9243

Attachments

File name MIME type
signature.asc application/pgp-signature

Replies

Subject Author
Re: [gentoo-hardened] SELinux updates Chris PeBenito <pebenito@g.o>