FC2T2 SELinux boot problem

Bernd Bartmann Bernd.Bartmann at sohanet.de
Fri Apr 2 19:00:21 UTC 2004


-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA1

Hi,

after a fresh install of FC2T2 the system came up and I run up2date to
update some packages and now my system won't boot anymore

Using the default kernel and SELinux in enforcing mode the boot process
hangs with:

audit(1080938712.685:0): avc:  denied  { read } for  pid=1
exe=/sbin/init name=null dev=hda3 ino=2310185
scontext=system_u:system_r:init_t tcontext=system_u:object_r:device_t
tclass=file

Using enforcing=0 in the kernel command line the system hangs at:

audit(1080938798.868:0): avc:  denied  { read } for  pid=29
exe=/sbin/consoletype
name=ld.so.cache dev=hda3 ino=1673828
scontext=system_u:system_r:consoletype_t tcontext=root:object_r:etc_t
tclass=file
audit(1080938799.100:0): avc:  denied  { getattr } for  pid=29
exe=/sbin/consoletype path=/etc/ld.so.cache dev=hda3 ino=1673828
scontext=system_u:system_r:consoletype_t tcontext=root:object_r:etc_t
tclass=file
audit(1080938799.943:0): avc:  denied  { read } for  pid=35
exe=/bin/dmesg name=ld.so.cache dev=hda3 ino=1673828
scontext=system_u:system_r:dmesg_t tcontext=root:object_r:etc_t tclass=file
audit(1080938800.160:0): avc:  denied  { getattr } for  pid=35
exe=/bin/dmesg path=/etc/ld.so.cache dev=hda3 ino=1673828
scontext=system_u:system_r:dmesg_t tcontext=root:object_r:etc_t tclass=file

Using selinux=0 in the kernel command line I get:

Warning: unable to open an initial console.
Kernel panic: Attempted to kill init!





Thanks in advance.

- --
Dipl.-Ing. (FH) Bernd Bartmann <Bernd.Bartmann at sohanet.de>
I.S. Security and Network Engineer
SoHaNet Technology GmbH / Kaiserin-Augusta-Allee 10-11 / 10553 Berlin
Fon: +49 30 214783-44 / Fax: +49 30 214783-46
-----BEGIN PGP SIGNATURE-----
Version: GnuPG v1.2.3 (GNU/Linux)
Comment: Using GnuPG with Mozilla - http://enigmail.mozdev.org

iD8DBQFAbbhFkQuIaHu84cIRAojnAJ9TYvtohPLbWxTJa1WStkYmGcl8gQCfYLOo
Z67GnSxoOkyB68jV611HTFk=
=TMXa
-----END PGP SIGNATURE-----





More information about the fedora-test-list mailing list