Research Menu

.
Skip Search Box

SELinux Mailing List

Re: How can modular policy ever have worked? [patch]

From: Erich Schubert <erich_at_debian.org>
Date: Mon, 20 Mar 2006 16:16:26 +0100


Hello Stephen,
> > Committing changes:
> > /usr/sbin/load_policy: Can't load policy: Invalid argument
> Any "security:" messages from the kernel in /var/log/messages upon the
> attempted policy load?

No. A strace shows that load_policy is writing data to the load interface,
which results in this invalid argument error: open("/selinux/load", O_RDWR|O_LARGEFILE) = 4 write(4, "\214\377|\371\10\0\0\0SE Linux\24\0\0\0\1\0\0\0\10\0\0"..., 592395) = -1 EINVAL (Invalid argument)

Any progress on the optional{} in base.pp issues? I have the impression that type attributes are broken; for example almost all (I can't say for sure, apol doesn't work for me; is there any other "policy decompiler"?) the restorecon_t relabelto rules are missing, which are defined for file_type. So I have the impression that when linking the base policy with optionals, these attributes are messed up.

best regards,
Erich Schubert

-- 
     erich@(vitavonni.de|debian.org)    --    GPG Key ID: 4B3A135C    (o_
  There is no branch of mathematics, however abstract, which may not  //\
 some day be applied to phenomena of the real world. --- Lobatchevsky V_/_
       Nichts läßt die Erde so geräumig erscheinen, als wenn man
           Freunde in der Ferne hat. --- Henry David Thoreau



--
This message was distributed to subscribers of the selinux mailing list.
If you no longer wish to subscribe, send mail to majordomo@tycho.nsa.gov with
the words "unsubscribe selinux" without quotes as the message.
Received on Mon 20 Mar 2006 - 10:17:02 EST
 

Date Posted: Jan 15, 2009 | Last Modified: Jan 15, 2009 | Last Reviewed: Jan 15, 2009

 
bottom

National Security Agency / Central Security Service