1 |
On Thu, 2008-03-13 at 22:19 +0100, Florian Tischler wrote: |
2 |
> I am trying to use SElinux in a Xen DomU. Profile is also |
3 |
> selinux/2007.0/hardened/amd64. I am using ~amd64 as accept_keywords, donĀ“t |
4 |
> know if this is a good idea when using selinux. |
5 |
> |
6 |
> I get exactly the same error messages like your error messages below + a few |
7 |
> additional one. (some of them are probably related to xen) |
8 |
[...] |
9 |
> audit(1205421548.959:24): avc: denied { getattr } for pid=1561 comm="bash" |
10 |
> name="xen" dev=proc ino=4026532902 scontext=system_u:system_r:initrc_t |
11 |
> tcontext=system_u:object_r:proc_xen_t tclass=dir |
12 |
> |
13 |
> audit(1205421548.959:25): avc: denied { search } for pid=1561 comm="bash" |
14 |
> name="xen" dev=proc ino=4026532902 scontext=system_u:system_r:initrc_t |
15 |
> tcontext=system_u:object_r:proc_xen_t tclass=dir |
16 |
> |
17 |
> audit(1205421548.959:26): avc: denied { read } for pid=1561 comm="bash" |
18 |
> name="capabilities" dev=proc ino=4026532943 |
19 |
> scontext=system_u:system_r:initrc_t tcontext=system_u:object_r:proc_xen_t |
20 |
> tclass=file |
21 |
> |
22 |
> audit(1205421548.963:27): avc: denied { getattr } for pid=1567 comm="grep" |
23 |
> name="capabilities" dev=proc ino=4026532943 |
24 |
> scontext=system_u:system_r:initrc_t tcontext=system_u:object_r:proc_xen_t |
25 |
> tclass=file |
26 |
|
27 |
Can you look through the init scripts to see whats going that it reads |
28 |
files in /proc/xen? |
29 |
|
30 |
-- |
31 |
Chris PeBenito |
32 |
<pebenito@g.o> |
33 |
Developer, |
34 |
Hardened Gentoo Linux |
35 |
|
36 |
Public Key: http://pgp.mit.edu:11371/pks/lookup?op=get&search=0xE6AF9243 |
37 |
Key fingerprint = B0E6 877A 883F A57A 8E6A CB00 BC8E E42D E6AF 9243 |