[gentoo-hardened] Portage-related AVCs

2016-11-23 Thread Robert Sharp
Hi, just done my weekly update and I noticed the following AVCs occurred that suggest something missing in the portage policy? type=PROCTITLE msg=audit(1479900756.052:3548): proctitle=6370002D61002D2D7265666C696E6B3D6175746F002F7661722F746D702F706F72746167652F6465762D707974686F6E2F70797061782

Re: [gentoo-hardened] Portage-related AVCs

2016-11-23 Thread Jason Zaman
On Wed, Nov 23, 2016 at 12:58:34PM +, Robert Sharp wrote: > Hi, > > just done my weekly update and I noticed the following AVCs occurred > that suggest something missing in the portage policy? > > type=PROCTITLE msg=audit(1479900756.052:3548): > proctitle=6370002D61002D2D7265666C696E6B3D617

Re: [gentoo-hardened] Portage-related AVCs

2016-11-23 Thread Robert Sharp
On 23/11/16 14:37, Jason Zaman wrote: Are you on ~arch or stable? did you just upgrade to the 2.6 userland? What versions do you have installed of these: sys-libs/libsepol sys-libs/libselinux sys-libs/libsemanage sys-apps/checkpolicy sys-apps/policycoreutils dev-python/sepolgen app-admin/setools

Re: [gentoo-hardened] Portage-related AVCs

2016-11-23 Thread Jason Zaman
On Wed, Nov 23, 2016 at 03:16:44PM +, Robert Sharp wrote: > > On 23/11/16 14:37, Jason Zaman wrote: > > Are you on ~arch or stable? did you just upgrade to the 2.6 userland? > > What versions do you have installed of these: > > sys-libs/libsepol > > sys-libs/libselinux > > sys-libs/libsemanage

Re: [gentoo-hardened] Portage-related AVCs

2016-11-23 Thread Robert Sharp
On 23/11/16 15:58, Jason Zaman wrote: Either is fine, but im probably just gonna stabilize the 2.6 userspace in a couple weeks so that one is likely easier. and setools4 is waaay better than 3. The important point is that you dont want to have both policy.29 and policy.30 around. Then you get we

Re: [gentoo-hardened] Portage-related AVCs

2016-11-23 Thread Jason Zaman
On Wed, Nov 23, 2016 at 04:59:03PM +, Robert Sharp wrote: > > On 23/11/16 15:58, Jason Zaman wrote: > > Either is fine, but im probably just gonna stabilize the 2.6 userspace > > in a couple weeks so that one is likely easier. and setools4 is waaay > > better than 3. The important point is tha

Re: [gentoo-hardened] Portage-related AVCs

2016-11-23 Thread Robert Sharp
On 23/11/16 16:59, Robert Sharp wrote: On 23/11/16 15:58, Jason Zaman wrote: Either is fine, but im probably just gonna stabilize the 2.6 userspace in a couple weeks so that one is likely easier. and setools4 is waaay better than 3. The important point is that you dont want to have both policy.

Re: [gentoo-hardened] Portage-related AVCs

2016-11-23 Thread Jason Zaman
On Wed, Nov 23, 2016 at 05:20:59PM +, Robert Sharp wrote: > On 23/11/16 16:59, Robert Sharp wrote: > > > > On 23/11/16 15:58, Jason Zaman wrote: > >> Either is fine, but im probably just gonna stabilize the 2.6 userspace > >> in a couple weeks so that one is likely easier. and setools4 is waaay