Gentoo Forums
Gentoo Forums
Gentoo Forums
Quick Search: in
!!! SELinux not loaded: SELinux is not enabled.
View unanswered posts
View posts from last 24 hours

 
Reply to topic    Gentoo Forums Forum Index Installing Gentoo
View previous topic :: View next topic  
Author Message
_puck_
Tux's lil' helper
Tux's lil' helper


Joined: 12 May 2002
Posts: 111
Location: Kaiserslautern / Germany

PostPosted: Sat Apr 24, 2004 2:31 pm    Post subject: !!! SELinux not loaded: SELinux is not enabled. Reply with quote

Hello there.

I'm currently installing gentoo-selinux ... after the first reboot is done, I want to relabel the fs:

Code:

dantuin root # cd /etc/security/selinux/src/policy
dantuin policy # make relabel
/usr/sbin/setfiles file_contexts/file_contexts `mount | grep -v "context=" | awk '/(ext[23]| xfs).*rw/{print $3}'`
/usr/sbin/setfiles:  read 559 specifications
/usr/sbin/setfiles:  invalid context system_u:object_r:default_t on line number 39
/usr/sbin/setfiles:  invalid context system_u:object_r:root_t on line number 44
/usr/sbin/setfiles:  invalid context system_u:object_r:home_root_t on line number 53
/usr/sbin/setfiles:  invalid context system_u:object_r:user_home_dir_t on line number 54
/usr/sbin/setfiles:  invalid context system_u:object_r:user_home_t on line number 55
/usr/sbin/setfiles:  invalid context system_u:object_r:mnt_t on line number 59
/usr/sbin/setfiles:  invalid context system_u:object_r:var_t on line number 64
/usr/sbin/setfiles:  invalid context system_u:object_r:catman_t on line number 65
/usr/sbin/setfiles:  invalid context system_u:object_r:catman_t on line number 66
/usr/sbin/setfiles:  invalid context system_u:object_r:var_yp_t on line number 67
Exiting after 10 errors.
make: *** [relabel] Error 1


When doing emerge -s xfs, I get:
Code:

!!! SELinux not loaded: SELinux is not enabled.
[...]


Any clues?
_________________
regards
puck
___________________________
#There is more than one way to do it.
Back to top
View user's profile Send private message
nixnut
Bodhisattva
Bodhisattva


Joined: 09 Apr 2004
Posts: 10974
Location: the dutch mountains

PostPosted: Sat Apr 24, 2004 8:35 pm    Post subject: Reply with quote

Looks like you need to build a selinux enabled kernel.
Back to top
View user's profile Send private message
_puck_
Tux's lil' helper
Tux's lil' helper


Joined: 12 May 2002
Posts: 111
Location: Kaiserslautern / Germany

PostPosted: Sat Apr 24, 2004 8:42 pm    Post subject: Reply with quote

pebenito in the irc-Channel helped me out. I had do modify the policy Makefile. The info was in the selinux-policy guide: Chapter 6: Policy Database Versions.
_________________
regards
puck
___________________________
#There is more than one way to do it.
Back to top
View user's profile Send private message
nixnut
Bodhisattva
Bodhisattva


Joined: 09 Apr 2004
Posts: 10974
Location: the dutch mountains

PostPosted: Sat Apr 24, 2004 8:50 pm    Post subject: Reply with quote

Aha, new kernel version, so new policy number.
Back to top
View user's profile Send private message
_puck_
Tux's lil' helper
Tux's lil' helper


Joined: 12 May 2002
Posts: 111
Location: Kaiserslautern / Germany

PostPosted: Sat Apr 24, 2004 8:57 pm    Post subject: Reply with quote

I am not that firm with the selinux. I am just playing a bit at the moment, trying to get this in production state (somewhere in the far future).

I have to learn a lot more, I know now. ;)
_________________
regards
puck
___________________________
#There is more than one way to do it.
Back to top
View user's profile Send private message
nixnut
Bodhisattva
Bodhisattva


Joined: 09 Apr 2004
Posts: 10974
Location: the dutch mountains

PostPosted: Sat Apr 24, 2004 8:59 pm    Post subject: Reply with quote

Me too :wink:
_________________
Please add [solved] to the initial post's subject line if you feel your problem is resolved. Help answer the unanswered

talk is cheap. supply exceeds demand
Back to top
View user's profile Send private message
exklusve
Apprentice
Apprentice


Joined: 23 Aug 2002
Posts: 270
Location: currently ~/

PostPosted: Wed Aug 04, 2004 1:24 am    Post subject: Reply with quote

Hey guys i've ran into the same problem.
Could you please post a link to
Quote:
The info was in the selinux-policy guide: Chapter 6: Policy Database Versions.

It would be much appreciated.
:)

Thanx!
_________________
eXklusve

You do know that no one gives a shit about your system spec's right?
Back to top
View user's profile Send private message
nixnut
Bodhisattva
Bodhisattva


Joined: 09 Apr 2004
Posts: 10974
Location: the dutch mountains

PostPosted: Wed Aug 04, 2004 6:47 pm    Post subject: Reply with quote

Here you are:
http://www.gentoo.org/proj/en/hardened/selinux/selinux-policy.xml
_________________
Please add [solved] to the initial post's subject line if you feel your problem is resolved. Help answer the unanswered

talk is cheap. supply exceeds demand
Back to top
View user's profile Send private message
decryption69
n00b
n00b


Joined: 13 Jul 2004
Posts: 3

PostPosted: Wed Aug 04, 2004 8:32 pm    Post subject: Reply with quote

you need to mount /mnt/gentoo/selinux with the selinuxfs

mount -t selinuxfs none /mnt/gentoo/selinux

I had the same problem, as well I was using a 2004.1 boot CD and not a selinux boot cd

http://www.gentoo.org/proj/en/hardened/selinux/selinux-x86-install.xml

Boot CD from:

http://gentoo.oregonstate.edu/experimental/x86/livecd/x86.
Back to top
View user's profile Send private message
Display posts from previous:   
Reply to topic    Gentoo Forums Forum Index Installing Gentoo All times are GMT
Page 1 of 1

 
Jump to:  
You cannot post new topics in this forum
You cannot reply to topics in this forum
You cannot edit your posts in this forum
You cannot delete your posts in this forum
You cannot vote in polls in this forum