Gentoo Archives: gentoo-hardened

From: Sven Vermeulen <swift@g.o>
To: gentoo-hardened@l.g.o
Subject: Re: [gentoo-hardened] Some Selinux questions on a fresh install
Date: Sun, 24 Feb 2013 19:44:04
Message-Id: 20130224194401.GB26847@gentoo.org
In Reply to: Re: [gentoo-hardened] Some Selinux questions on a fresh install by Luis Ressel
1 On Sun, Feb 24, 2013 at 04:30:28PM +0100, Luis Ressel wrote:
2 > > I also notice a lot of capability (mknod) requests in the denials -
3 > > again, without noticeable change in behavior. Very awkward to debug -
4 > > I can't just dontaudit it (not convinced they aren't needed) nor
5 > > allow (not convinced they are needed) :-/
6 >
7 > That's caused by a new grsecurity feature in hardened-sources-3.7.5,
8 > I filed a bug about that a week ago:
9 > https://bugs.gentoo.org/show_bug.cgi?id=457812
10
11 You saved me (probably) a couple of hours of brain-pain ;)
12
13 Wkr,
14 Sven Vermeulen