Gentoo Archives: gentoo-hardened

From: Chris PeBenito <pebenito@g.o>
To: gentoo-hardened@l.g.o
Subject: Re: [gentoo-hardened] Problem with SELinux policy
Date: Thu, 20 Mar 2008 13:23:07
Message-Id: 1206019345.5091.12.camel@defiant.pebenito.net
In Reply to: Re: [gentoo-hardened] Problem with SELinux policy by Florian Tischler
1 On Thu, 2008-03-13 at 22:19 +0100, Florian Tischler wrote:
2 > I am trying to use SElinux in a Xen DomU. Profile is also
3 > selinux/2007.0/hardened/amd64. I am using ~amd64 as accept_keywords, donĀ“t
4 > know if this is a good idea when using selinux.
5 >
6 > I get exactly the same error messages like your error messages below + a few
7 > additional one. (some of them are probably related to xen)
8 [...]
9 > audit(1205421548.959:24): avc: denied { getattr } for pid=1561 comm="bash"
10 > name="xen" dev=proc ino=4026532902 scontext=system_u:system_r:initrc_t
11 > tcontext=system_u:object_r:proc_xen_t tclass=dir
12 >
13 > audit(1205421548.959:25): avc: denied { search } for pid=1561 comm="bash"
14 > name="xen" dev=proc ino=4026532902 scontext=system_u:system_r:initrc_t
15 > tcontext=system_u:object_r:proc_xen_t tclass=dir
16 >
17 > audit(1205421548.959:26): avc: denied { read } for pid=1561 comm="bash"
18 > name="capabilities" dev=proc ino=4026532943
19 > scontext=system_u:system_r:initrc_t tcontext=system_u:object_r:proc_xen_t
20 > tclass=file
21 >
22 > audit(1205421548.963:27): avc: denied { getattr } for pid=1567 comm="grep"
23 > name="capabilities" dev=proc ino=4026532943
24 > scontext=system_u:system_r:initrc_t tcontext=system_u:object_r:proc_xen_t
25 > tclass=file
26
27 Can you look through the init scripts to see whats going that it reads
28 files in /proc/xen?
29
30 --
31 Chris PeBenito
32 <pebenito@g.o>
33 Developer,
34 Hardened Gentoo Linux
35
36 Public Key: http://pgp.mit.edu:11371/pks/lookup?op=get&search=0xE6AF9243
37 Key fingerprint = B0E6 877A 883F A57A 8E6A CB00 BC8E E42D E6AF 9243

Attachments

File name MIME type
signature.asc application/pgp-signature