Bug 188068
Summary: | FC4 kernel doesn't understand MLS | ||||||
---|---|---|---|---|---|---|---|
Product: | [Fedora] Fedora | Reporter: | Ron Yorston <rmy> | ||||
Component: | kernel | Assignee: | Kernel Maintainer List <kernel-maint> | ||||
Status: | CLOSED ERRATA | QA Contact: | Brian Brock <bbrock> | ||||
Severity: | medium | Docs Contact: | |||||
Priority: | medium | ||||||
Version: | 4 | CC: | jmorris, sdsmall, wtogami | ||||
Target Milestone: | --- | ||||||
Target Release: | --- | ||||||
Hardware: | i686 | ||||||
OS: | Linux | ||||||
Whiteboard: | |||||||
Fixed In Version: | 2.6.16-1.2107_FC4 | Doc Type: | Bug Fix | ||||
Doc Text: | Story Points: | --- | |||||
Clone Of: | Environment: | ||||||
Last Closed: | 2006-05-03 19:26:48 UTC | Type: | --- | ||||
Regression: | --- | Mount Type: | --- | ||||
Documentation: | --- | CRM: | |||||
Verified Versions: | Category: | --- | |||||
oVirt Team: | --- | RHEL 7.3 requirements from Atomic Host: | |||||
Cloudforms Team: | --- | Target Upstream Version: | |||||
Embargoed: | |||||||
Attachments: |
|
Description
Ron Yorston
2006-04-05 18:21:47 UTC
I thought that this was resolved in bug 174618 and upstream in 2.6.15. But the reporter indicates that it is still causing problems. Bug 177349 tracks the RHEL4 fix. (In reply to comment #1) > I thought that this was resolved in bug 174618 and upstream in 2.6.15. > But the reporter indicates that it is still causing problems. > Bug 177349 tracks the RHEL4 fix. Oops, the latter should be bug 177439. Created attachment 127429 [details]
Fix MLS compatibility patch in 2.6.16
It looks as though it's an off-by-one issue. In mls_context_to_sid in mls.c
the parsing code is returning *scontext pointing to one beyond the terminating
null in the string. The compatibility code needs to add one more to *scontext
to allow for this.
With this patch added to the 2.6.16-1.2069_FC4 kernel I'm able to boot my FC4
installation in enforcing mode and access files in my shared /home. The
context_to_sid warnings have all gone.
Attachment 127429 [details] is correct (to the extent that the mls parsing code and length
check is correct, which can be debated, but that is another matter).
Acked-by: Stephen Smalley <sds.gov>
|