Gentoo Archives: gentoo-hardened

From: Robert Sharp <selinux@×××××××××××××××.org>
To: gentoo-hardened@l.g.o
Subject: Re: [gentoo-hardened] Portage-related AVCs
Date: Wed, 23 Nov 2016 16:59:15
Message-Id: 3d840d26-fadc-0350-094d-d84c36acd899@sharp.homelinux.org
In Reply to: Re: [gentoo-hardened] Portage-related AVCs by Jason Zaman
1 On 23/11/16 15:58, Jason Zaman wrote:
2 > Either is fine, but im probably just gonna stabilize the 2.6 userspace
3 > in a couple weeks so that one is likely easier. and setools4 is waaay
4 > better than 3. The important point is that you dont want to have both
5 > policy.29 and policy.30 around. Then you get weirdness like if you
6 > downgrade a kernel or something random it'll load in the old policy
7 > which probably doesnt work properly, so whichever you pick, make sure
8 > you nuke the other one. and semodule -B will rebuild the whole policy
9 > again and load it.
10 OK - I will go with policy.30 and add the keywords etc. I did a couple
11 of local policy changes that may not be needed so will they disappear in
12 all of this or do I need to remove them somehow first?
13
14 Thanks for all your help,
15 Robert

Replies

Subject Author
Re: [gentoo-hardened] Portage-related AVCs Jason Zaman <jason@×××××××××.com>
Re: [gentoo-hardened] Portage-related AVCs Robert Sharp <selinux@×××××××××××××××.org>