Vitavonni

Thu, 29 Jul 2004

More SELinux

Proceeding with my SELinux experience wrapup:

  • never call /etc/init.d/something. Use run_init /etc/init.d/something. It usually will appear to have worked, but the contexts will be wrong and you'll get odd violations. (i've read that the fedora guys have found a way for at least cron to transition into its proper domain automatically)
  • never use apt-get or dpkg in a modifying call directly. Use se_dpkg and se_apt-get. In fact i recommend adding an alias. (you'll survive having to enter your password for things like "dpkg -L", or use /usr/bin/dpkg) I bet these things could be avoided if one would make apt-get and dpkg selinux-aware, but unless selinux is in main i prefer this wrapper-solution.
  • avoid things like "audit2allow". Try to understand the macros and write proper policy rules. Use "dontaudit" when the access is not needed. For example: dontaudit { dpkg_t apt_t } newrole_t:fd { use };

Fucked today in unstable: cron. If you don't need "crontab", you can just touch /usr/bin/crontab and it will configure and cron should run. But no crontab editing until the next upload (which probably is in incoming)

Menu
[planet.debian]
[planet.xmlhack]
[planet SELinux]
[munichblogs]
[email]
[RSS 2 feed]
[English RSS 2]
Categories
July 2004 >
SuMoTuWeThFrSa
     1 2 3
4 5 6 7 8 910
11121314151617
18192021222324
25262728293031
Archives
2010-Mar
2010-Feb
2010-Jan
2009-Dec
2009-Nov
2009-Oct
2009-Sep
2009-Aug
2009-Jul
2009-Jun
2009-May
2009-Apr
2009-Mar
2009-Feb
2009-Jan
2008-Dec
2008-Nov
2008-Oct
2008-Sep
2008-Aug
2008-Jul
2008-May
2008-Apr
2008-Mar
2008-Feb
2008-Jan
2007-Dec
2007-Nov
2007-Oct
2007-Sep
2007-Aug
2007-Jul
2007-Jun
2007-May
2007-Apr
2007-Mar
2007-Feb
2007-Jan
2006-Dec
2006-Nov
2006-Oct
2006-Sep
2006-Aug
2006-Jul
2006-Jun
2006-May
2006-Apr
2006-Mar
2006-Feb
2006-Jan
2005-Dec
2005-Nov
2005-Oct
2005-Sep
2005-Aug
2005-Jul
2005-Jun
2005-May
2005-Apr
2005-Mar
2005-Feb
2005-Jan
2004-Dec
2004-Nov
2004-Oct
2004-Sep
2004-Aug
2004-Jul
Other links:
Swing and the City - Lindy Hop in Munich