Gentoo Archives: gentoo-hardened

From: kakou <kakou@×××××.org>
To: gentoo-hardened@l.g.o
Subject: Re: [gentoo-hardened] New selinux-policy ebuild don't install anything ??
Date: Wed, 25 Oct 2006 12:44:54
Message-Id: 1161780128.27246.19.camel@po-briffaut.kakou.org
In Reply to: Re: [gentoo-hardened] New selinux-policy ebuild don't install anything ?? by Chris PeBenito
1 Le mercredi 25 octobre 2006 à 07:30 -0400, Chris PeBenito a écrit :
2 > On Wed, 2006-10-25 at 10:04 +0200, kakou wrote:
3 > > Le mardi 24 octobre 2006 à 23:03 -0400, Chris PeBenito a écrit :
4 > > > On Tue, 2006-10-24 at 17:12 +0200, kakou wrote:
5 > > > > Le dimanche 22 octobre 2006 à 01:04 -0400, Chris PeBenito a écrit :
6 > > > > > On Fri, 2006-10-20 at 20:01 +0200, kakou wrote:
7 > > > > > > I try to update my selinux system but all new selinux-policy ebuild
8 > > > > > > install any files (or not interresting files):
9 > > > > > >
10 > > > > > > >>> Emerging (1 of 1) sec-policy/selinux-base-policy-20061015 to /
11 > > > > >
12 > > > > > > >>> Merging sec-policy/selinux-base-policy-20061015 to /
13 > > > > > > - --- /etc/
14 > > > > > > - --- /etc/selinux/
15 > > > > > > >>> /etc/selinux/config
16 > > > > > > - --- /usr/
17 > > > > > > - --- /usr/share/
18 > > > > > > - --- /usr/share/doc/
19 > > > > > > - --- /usr/share/doc/selinux-base-policy-20061015/
20 > > > > > > >>> /usr/share/doc/selinux-base-policy-20061015/example.fc.gz
21 > > > > > > >>> /usr/share/doc/selinux-base-policy-20061015/example.if.gz
22 > > > > > > >>> /usr/share/doc/selinux-base-policy-20061015/example.te.gz
23 > > > > > > >>> /usr/share/doc/selinux-base-policy-20061015/Makefile.example.gz
24 > > > > >
25 > > > > > It certainly installs more than this. I can't reproduce this, and the
26 > > > > > other testers haven't either :x
27 > > > > >
28 > > > > It's maybe because I'm on a no selinux system (not hardened and without
29 > > > > selinux useflag)?
30 > > > > I have a similar problem with setools-3 that need a selinuxfs and so
31 > > > > crash during compilation.
32 > > >
33 > > > Thats it. Your system should be using the SELinux profile, as described
34 > > > in the SELinux conversion guide.
35 > > >
36 > >
37 > > Yes, but on my laptop, I just need the selinux-policy in order to build
38 > > the binary policy. I am not using and I want not to use real selinux
39 > > system on this machine, I just need the binrary computed with lasted
40 > > policy source.
41 > > They are not a means to bypass this problem ?
42 >
43 > Since this is a reasonable thing to do, I fixed the ebuild to work on
44 > non SELinux profiles.
45 >
46 Ok thank you
47
48 For the setools problem, I have added and mounted /selinux and it
49 compiles

Attachments

File name MIME type
signature.asc application/pgp-signature