Gentoo Archives: gentoo-hardened

From: Panagiotis Atmatzidis <p.atmatzidis@×××××.com>
To: gentoo-hardened@l.g.o
Subject: Re: [gentoo-hardened] selinux newbie questions / avc denies everything
Date: Tue, 21 Mar 2006 06:55:44
Message-Id: 441FA30C.5000204@gmail.com
In Reply to: Re: [gentoo-hardened] selinux newbie questions / avc denies everything by Thomas Eschenbacher
1 Thomas Eschenbacher wrote:
2 > Chris PeBenito wrote:
3 >> [...]
4 >> Unfortunately this is your problem:
5 >>
6 >>> kernel "2.6.14-hardened-r5",
7 >>> XFS as root filesystem
8 >> please see: http://marc.theaimsgroup.com/?l=gentoo-hardened&m=113433863728029&w=2
9 >>
10 >> XFS should be fixed in 2.6.16.
11 >
12 > Thanks for your quick reply!
13 > So it seems that I have the following options:
14 >
15 > A) wait some weeks (or months?) until 2.6.16-hardened is out, run in
16 > permissive mode meanwhile.
17 >
18 > B) take the sources of kernel 2.6.16-rc6, apply the SELinux patch
19 > against it and replace the "fs/xfs" directory of my old
20 > 2.6.14-hardened-r5 source tree with the one from the new version. Will
21 > this "backport" work, is this compatible?
22 >
23 > C) switch to a different filesystem. My only options seem to be:
24 > 1. ext2/ext3 -> I hate running e2fsck, no options.
25 > 2. reiserfs -> officially unsupported for SELinux
26 > 3. XFS -> obviously doesn't work in this version
27 > 4. JFS -> any experience?
28
29 Yes. Avoid JFS under GNU/Linux this like the plague.
30
31 >
32 > Any suggestions or other alternatives?
33
34 I'd A or C1.
35
36 > Thomas
37
38 --
39 gentoo-hardened@g.o mailing list

Replies

Subject Author
Re: [gentoo-hardened] selinux newbie questions / avc denies everything Thomas Eschenbacher <Thomas.Eschenbacher@×××.de>