Re: 2.6.27-rc1: strange fstab issue (Re: 2.6.27-rc1 + selinux new options = no httpd)

!MAILaRCHIVE_VOTE_RePLACE
Previous message: [thread] [date] [author]
Next message: [thread] [date] [author]
To: Gene Heskett <gene.heskett@...>
Cc: Rafael J. Wysocki <rjw@...>, James Morris <jmorris@...>, <linux-kernel@...>, Stephen Smalley <sds@...>, <aviro@...>
Date: Friday, August 1, 2008 - 9:47 am

On Fri, 2008-08-01 at 09:39 -0400, Gene Heskett wrote:

Stephen Smalley just sent me a private note.  Apparently he is having
e-mail trouble but he did point out the most likely problem.  Can you
add the patch from

http://marc.info/?l=linux-kernel&m=121726661110266&w=2

And give it a whirl?  Sorry, but we think the problem is that the VFS
stopped passing all of the relevant information down to the security
system.  https is only allowed to append to its log files, not actually
'write.'  Since the VFS is longer differentiating those two operations
you are getting then denial for write.

I'll try to get this pushed into linus's tree quickly.

-Eric

--
Previous message: [thread] [date] [author]
Next message: [thread] [date] [author]

Messages in current thread:
2.6.27-rc1 + selinux new options = no httpd, Gene Heskett, (Wed Jul 30, 10:54 pm)
Re: 2.6.27-rc1 + selinux new options = no httpd, James Morris, (Thu Jul 31, 12:43 am)
Re: 2.6.27-rc1 + selinux new options = no httpd, Gene Heskett, (Thu Jul 31, 9:09 am)
Re: 2.6.27-rc1 + selinux new options = no httpd, James Morris, (Thu Jul 31, 4:02 pm)
2.6.27-rc1: strange fstab issue (Re: 2.6.27-rc1 + selinux ne..., Rafael J. Wysocki, (Thu Jul 31, 6:17 pm)
Re: 2.6.27-rc1: strange fstab issue (Re: 2.6.27-rc1 + selinu..., Eric Paris, (Fri Aug 1, 9:47 am)
Re: 2.6.27-rc1 + selinux new options = no httpd, Eric Paris, (Thu Jul 31, 10:44 am)
Re: 2.6.27-rc1 + selinux new options = no httpd, Stephen Smalley, (Thu Jul 31, 1:47 pm)
Re: 2.6.27-rc1 + selinux new options = no httpd, Gene Heskett, (Fri Aug 1, 2:52 pm)
Re: 2.6.27-rc1 + selinux new options = no httpd, Stephen Smalley, (Fri Aug 1, 8:51 am)
Re: 2.6.27-rc1 + selinux new options = no httpd, Al Viro, (Fri Aug 1, 10:47 am)