Research
.
Skip Search Box

SELinux Mailing List

RE: Kernel panic when using refpolicy

From: Kim Lawson-Jenkins <lawson_at_itd.nrl.navy.mil>
Date: Fri, 7 Sep 2007 13:56:58 -0500


Chris (and Eric & Brian),

I was running in permissive mode and yes, I did have TYPE=targeted, not TYPE=targeted-mcs. I'll make the change. Thanks everyone for the responses.

Kim

-----Original Message-----
From: Christopher J. PeBenito [mailto:cpebenito@tresys.com] Sent: Friday, September 07, 2007 12:44 PM To: Kim Lawson-Jenkins
Cc: selinux@tycho.nsa.gov
Subject: Re: Kernel panic when using refpolicy

On Fri, 2007-09-07 at 13:14 -0500, Kim Lawson-Jenkins wrote:
> I'm running RHEL5. I downloaded refpolicy-20070629.tar.bz2 and
> selinux-refpolicy-sources-20070629-1.noarch.rpm and installed the files
for
> the reference policy. When rebooting the system there was a fatal error -
> Kernel panic - not syncing: Fatal exception.
>
> There were many unknown Boolean errors for libsepol.load.booleans and
there
> was the following error -
> libsepol.sepol_genbools: error while reading
/etc/selinux/refpolicy/Booleans
>
> It looks like ifconfig was running when the kernel panic occurred. To
> recover booted into single-user mode and changed the SELINUXTYPE in the
file
> /etc/selinux/config from refpolicy to targeted. I can easily repeat the
> problem by using the SELinux Management Tool to change the System Default
> Policy Type from targeted to refpolicy and rebooting. I've looked at all
of
> the documentation to see if I missed a step or downloaded an incorrect
file
> but I can't find anything. Can anyone give me some insight into what the
> problem may be? Thanks in advance for a response.

You set TYPE=targeted, not TYPE=targeted-mcs, right? If so, I suspect that you've hit the kernel bug in RHEL5 that happens when the SELinux MLS support is disabled. Loading a MCS policy turns on the MLS support. In fact the RHEL5 targeted policy is targeted-mcs, in refpolicy terms.

-- 
Chris PeBenito
Tresys Technology, LLC
(410) 290-1411 x150


--
This message was distributed to subscribers of the selinux mailing list.
If you no longer wish to subscribe, send mail to majordomo@tycho.nsa.gov with
the words "unsubscribe selinux" without quotes as the message.
Received on Fri 7 Sep 2007 - 14:09:57 EDT
 

Date Posted: Jan 15, 2009 | Last Modified: Jan 15, 2009 | Last Reviewed: Jan 15, 2009

 
bottom

National Security Agency / Central Security Service