Gentoo Archives: gentoo-hardened

From: Tiago Lima <tiago.lima@×××××.pt>
To: Chris PeBenito <pebenito@g.o>, cmulcahy@×××××.com
Cc: gentoo-hardened@l.g.o
Subject: Re: [gentoo-hardened] Re: SELinux Issues
Date: Fri, 09 Jan 2004 11:41:39
Message-Id: 200401091141.16531.tiago.lima@vianw.pt
In Reply to: Re: [gentoo-hardened] Re: SELinux Issues by Chris PeBenito
1 Hi,
2
3 On Thursday 08 January 2004 04:30, Chris PeBenito wrote:
4 > Delete the devfsd.te and devfsd.fc, reload, relabel (devfsd at least).
5
6 What do you mean by "relabel (devfsd at least)" ?
7
8 > Since devfs doesn't work on the new API, I removed the policy for it.
9 > Unfortunately the config protection prevents it from being removed when
10 > the policy is updated. I'll make a note of it in the changelog.
11
12 So for now just deleting the devfsd.te and devfsd.fc files and "make load" (or
13 make reload ?) and make relabel (followed by a reboot ?) should work ?
14
15 Another thing, when we do :
16
17 $ make install
18 $ make initrd
19
20 it generates a initrd.gz file in the /boot directory, isnt it? How can I
21 change the name of the file to be generated ?
22
23 Does the policy has anything to do with the kernel version / features ? For
24 example if I use a newer kernel and an older policy it should work also ? And
25 vice-versa ?
26
27 >
28 > On Wed, 2004-01-07 at 19:36, cmulcahy@×××××.com wrote:
29 > > There is might (likely) be a better solution.
30 > >
31 > > >> relabelto }; assertion on line 37285 violated by allow devfsd_t
32 > > >> etc_t:dir {
33
34 Thanks in advance,
35 Tiago Lima
36
37
38 --
39 gentoo-hardened@g.o mailing list

Replies

Subject Author
Re: [gentoo-hardened] Re: SELinux Issues Chris PeBenito <pebenito@g.o>