Research
.
Skip Search Box

SELinux Mailing List

Re: You mentioned somewhere there is a step by step guide to getting the MLS policy installed on a machine?

From: Luke Kenneth Casson Leighton <lkcl_at_lkcl.net>
Date: Thu, 14 Apr 2005 23:52:07 +0100


On Thu, Apr 14, 2005 at 04:38:13PM -0400, Stephen Smalley wrote:

> 3) Rather than immediately booting the MLS-enabled kernel into multi-
> user mode, you should instead boot with enforcing=0 single to fix up the
> context on /etc/mtab, which is re-created by the shutdown while you were
> still running with selinux=0. You can run /sbin/restorecon /etc/mtab
> from single-user mode, then /usr/sbin/setenforce 1 and exit the single-
> user shell to come up multi-user.

 /etc/mtab is/was an issue (not in MLS) iirc with debian - it  was the cause of much grief - esp. when a program didn't exit  at shutdown, locked the partition (e.g. /usr), caused umount  to fail, cascade-caused /etc/mtab to not be updated, there's  a bug in /etc/init.d/mountvirtfs.sh where it incorrectly  detect(s/ed?) that /etc/mtab wasn't writeable, cascade-caused  mountvirtfs.sh to think that /usr was still mounted read-write  from the prior shutdown, and it went pear-shaped from there.

 l.

--
This message was distributed to subscribers of the selinux mailing list.
If you no longer wish to subscribe, send mail to majordomo@tycho.nsa.gov with
the words "unsubscribe selinux" without quotes as the message.
Received on Thu 14 Apr 2005 - 18:46:58 EDT
 

Date Posted: Jan 15, 2009 | Last Modified: Jan 15, 2009 | Last Reviewed: Jan 15, 2009

 
bottom

National Security Agency / Central Security Service