Gentoo Archives: gentoo-hardened

From: Sven Vermeulen <swift@g.o>
To: gentoo-hardened@l.g.o
Subject: Re: [gentoo-hardened] Running rc-service without run_init
Date: Sun, 12 Jan 2014 21:02:36
Message-Id: 20140112210233.GA1615@gentoo.org
In Reply to: Re: [gentoo-hardened] Running rc-service without run_init by "Dustin C. Hatch"
1 On Sun, Jan 12, 2014 at 11:44:56AM -0600, Dustin C. Hatch wrote:
2 > >> I think I found it. It seemed that the integrated run_init support, provided
3 > >> through the runscript_selinux.so library that we provide (for OpenRC) didn't
4 > >> use PAM authentication, even when policycoreutils was built with USE="pam".
5 > >>
6 > >> This is because the ebuild didn't use the python-r1.eclass BUILD_DIR
7 > >> location (where the files were compiled earlier in the phase) but the
8 > >> "normal" ${S} location (which contains the sources). As a result, the "make
9 > >> install" phase started building the code, without taking the various USE
10 > >> flags into account, and then installing those files.
11 [...]
12 > > Cool, I've kicked off a catalyst rebuild of my SELinux stage[1234] and
13 > > will deploy a new test VM as soon as its done. I'll let you know how it
14 > > goes.
15 > >
16 > > Thanks again for your help.
17 > >
18 > It is indeed working now, thank you. Is there any chance this can be
19 > backported to 2.1?
20
21 Certainly; policycoreutils-2.1.14-r5 is now in tree with the same fix.
22
23 Wkr,
24 Sven Vermeulen