[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]

Re: [Xen-devel] XSM/Flask and SELinux policy Compiler problem


  • To: "Ahmed, Farid" <Farid.Ahmed@xxxxxxxxxx>, xen-devel <xen-devel@xxxxxxxxxxxxxxxxxxx>
  • From: "George S. Coker, II" <gscoker@xxxxxxxxxxxxxx>
  • Date: Mon, 20 Oct 2008 18:37:42 -0400
  • Cc:
  • Delivery-date: Mon, 20 Oct 2008 15:38:15 -0700
  • List-id: Xen developer discussion <xen-devel.lists.xensource.com>
  • Thread-index: Ackyt0UanDIKAh16RpOi2Q5AdX5L1wAAQ/sgABMIZ/c=
  • Thread-topic: [Xen-devel] XSM/Flask and SELinux policy Compiler problem

I'm not sure why selinux is not enabled in your guest.  If you are not
intentionally disabling selinux, I guess that you probably don't have
selinux properly enabled in your kernel.  Selinux is not part of the stock
xenolinux config.

Unfortunately, you've uncovered some selinux cruft in the sample policy.
You need to comment out the line in the makefile that checks
/selinux/policyvers.  This should allow the policy build to continue.
Nothing in the sample policy depends on this value.

George


On 10/20/08 9:41 AM, "Ahmed, Farid" <Farid.Ahmed@xxxxxxxxxx> wrote:

>  
> Hi,
> While booting my Linux box with  Fedora Core 8 with Xen-unstable (Xen
> 3.4?) [ Kernel version 2.6.18.8-xen], it appears that SELinux is not
> mounted. The error/warning message is:
> 
> Mount failed for selinuxfs on /selinux
> 
> As  a result the XSM-Flask policy compiler stops building due not to
> have access to /selinux/policyvers.
> 
>  Did anyone  encounter this problem? Any suggestion to get over with
> this?
> Thanks
> 
> Farid
> 
> _______________________________________________
> Xen-devel mailing list
> Xen-devel@xxxxxxxxxxxxxxxxxxx
> http://lists.xensource.com/xen-devel

-- 
George S. Coker, II <gscoker@xxxxxxxxxxxxxx>



_______________________________________________
Xen-devel mailing list
Xen-devel@xxxxxxxxxxxxxxxxxxx
http://lists.xensource.com/xen-devel


 


Rackspace

Lists.xenproject.org is hosted with RackSpace, monitoring our
servers 24x7x365 and backed by RackSpace's Fanatical Support®.