Research Menu

.
Skip Search Box

SELinux Mailing List

Re: [POLICY/PATCH] IA-64 Boot Partition

From: Christopher J. PeBenito <cpebenito_at_tresys.com>
Date: Sat, 16 Apr 2005 11:55:59 -0400


On Sat, 2005-04-16 at 15:57 +0900, KaiGai Kohei wrote:
> This attached patch modifies genfs_contexts.
> When arch_ia64 is defined in tunable/tunable.tun,
> vfat is labeled as boot_t, not dosfs_t.
>
> Currently, vfat-fs is recognized as dosfs_t.
> But, vfat is often used as bootable partition
> which should be labeled as boot_t.
>
> In IA-64 Linux, any files related to booting process such as
> vmlinuz and initrd.img are placed under /boot/efi/.
> We must mount a vfat partition contains such files on /boot/efi,
> because EFI can't recognize the contents of Ext2/3 partitions.
> (EFI is a firmware similar to PC's BIOS.)
> # The kernel provided by RedHat is placed in /boot/efi/efi/redhat.

It would seem like mounting /boot with the context= mount option is a better solution. Vfat being mounted at /boot is an exception to the genfscon; there could be other vfat partitions you might want to mount, and they should be dosfs_t. So rather then making all vfat partitions boot_t on ia64, you should just mount /boot with the context= option.

-- 
Chris PeBenito
Tresys Technology, LLC
(410) 290-1411 x150



--
This message was distributed to subscribers of the selinux mailing list.
If you no longer wish to subscribe, send mail to majordomo@tycho.nsa.gov with
the words "unsubscribe selinux" without quotes as the message.
Received on Sat 16 Apr 2005 - 11:59:57 EDT
 

Date Posted: Jan 15, 2009 | Last Modified: Jan 15, 2009 | Last Reviewed: Jan 15, 2009

 
bottom

National Security Agency / Central Security Service