[refpolicy] pam_selinux(gdm-password:session): Security Context justin:staff_r:insmod_t:s0 Assigned

Justin P. Mattock justinmattock at yahoo.com
Fri Sep 16 11:33:55 CDT 2011


On 09/16/2011 09:27 AM, Guido Trentalancia wrote:
> On Fri, 2011-09-16 at 09:18 -0700, Justin P. Mattock wrote:
>> On 09/16/2011 09:02 AM, Guido Trentalancia wrote:
>>> getsebool -a
>> at the bottom of the fpaste
>> as for init
>> lrwxrwxrwx. root root system_u:object_r:bin_t:s0       /sbin/init
>> ->  ../bin/systemd
> That's the label of the link. Need the label of the target:
>
> ls -lZ /bin/systemd
>
> or whatever that is.

then systemd is labelled correctly:
ls -lZ /bin/systemd
-rwxr-xr-x. root root system_u:object_r:init_exec_t:s0 /bin/systemd

as for a boolean, the only one I can see _remotely_ close to init_systemd=on
is init_upstart --> on in of which is set to on.

>
>> looks like somewhere somehow the label was labeled wrong.
>> stange, I loaded refpolicy(mcs) from fedora's targeted then did sudo
>> make relabel from refpolicy even fixfiles relabel at another point in
>> time. there is no patch needed for systemd? that needs to be added to
>> refpolicy-git?
> Moving from Fedora targeted to refpolicy mcs is not just exactly a very
> straight thing. As far as I remember when I first installed refpolicy I
> hit the init_upstart boolean issue. That's why I recommend you look up
> your init_systemd boolean:
>
> setsebool init_systemd=on
>
>> Justin P. Mattock
> Guido
>
Justin P. Mattock
-------------- next part --------------
An HTML attachment was scrubbed...
URL: http://oss.tresys.com/pipermail/refpolicy/attachments/20110916/85e3f59e/attachment.html 


More information about the refpolicy mailing list