[gentoo-hardened] selinux denials due to race conditions?

2007-06-20 Thread Bill Sharer
I'm on the 2006.1 unstable profile for selinux and think I may have a race condition that results in avc denials before selinux has finished labeling things like /dev. For example, the first denial below appears to be where /etc/hotplug.d/default/default.hotplug is peeking and poking around wi

Re: [gentoo-hardened] selinux denials due to race conditions?

2007-06-20 Thread Chris PeBenito
On Tue, 2007-06-19 at 20:55 -0400, Bill Sharer wrote: > I'm on the 2006.1 unstable profile for selinux and think I may have a > race condition that results in avc denials before selinux has finished > labeling things like /dev. For example, the first denial below appears > to be where /etc/hotpl

Re: [gentoo-hardened] selinux denials due to race conditions?

2007-06-20 Thread Joern Wittek
> I'm on the 2006.1 unstable profile for selinux and think I may have a > race condition that results in avc denials before selinux has finished > labeling things like /dev. For example, the first denial below appears > to be where /etc/hotplug.d/default/default.hotplug is peeking and poking > arou

Re: [gentoo-hardened] Re: Cannot boot a hardened-sources-2.4.33.4 on a SATA drive

2007-06-20 Thread Brant Williams
What error(s) do you see? Public GPG/PGP key for Brant Williams: 0x88E1AA9E. Available at your friendly local public keyserver. On Mon, 18 Jun 2007, René Rhéaume wrote: > No, the problem was SCSI and SCSI disk support were built as modules, > not in-kernel. Now, init runs, but e2fsck does no

Re: [gentoo-hardened] Re: Cannot boot a hardened-sources-2.4.33.4 on a SATA drive

2007-06-20 Thread René Rhéaume
On 6/20/07, Brant Williams <[EMAIL PROTECTED]> wrote: What error(s) do you see? e2fsck was doing a fatal error and I was forced to reboot. It is now solved after I updated e2fsprogs. Long answer : I restarted a hardened+uclibc installation using a very old stage3 tarball (dating back from 2005)