Research
.
Skip Search Box

SELinux Mailing List

Re: http://sf.net/projects/xen

From: Luke Kenneth Casson Leighton <lkcl_at_lkcl.net>
Date: Sun, 21 Nov 2004 01:05:42 +0000


On Sat, Nov 20, 2004 at 08:40:20PM +0000, Luke Kenneth Casson Leighton wrote:

> for those people who do a lot of selinux testing, and am fed up
> of having stacks of machines, and who also don't want to pay for
> vmware, _and_ who also don't want the slowness or features of UML,
> there is xen.

 okay - i am having difficulties with the network bridging and the  allocation of DHCP addresses: other than that, i have an selinux  "guest" kernel OS now up and running.

 the ext3 filesystem is in a file (mounted loopback automagically by xen)  make relabel seems happy...

 [DAMN IT i shut down the master linux os AGAIN by mistake.   kids, don't try this at home...]

 in the config file, e.g /etc/xen/xen-selinux-1, you will need  to place what they call "extra" parameters into the  config option extra="..." e.g

 extra="selinux=1 enforcing=1 audit=1"

 that sort of thing...

 oh _great_ i know selinux is working absolutely fine when i  can't damn well log in to the machine!!! log in as root, cannot  execute /bin/bash - greeeaat.

 [oops, pressing ctrl-alt-delete isn't caught / passed over to   the guest OS - that's _another_ accidental reboot.]  

 conclusion: it looks hopeful that xen will happily run selinux OSes.

 l.

--
This message was distributed to subscribers of the selinux mailing list.
If you no longer wish to subscribe, send mail to majordomo@tycho.nsa.gov with
the words "unsubscribe selinux" without quotes as the message.
Received on Sat 20 Nov 2004 - 19:54:57 EST
 

Date Posted: Jan 15, 2009 | Last Modified: Jan 15, 2009 | Last Reviewed: Jan 15, 2009

 
bottom

National Security Agency / Central Security Service