Return-Path: Received: (majordomo@vger.kernel.org) by vger.kernel.org via listexpand id S1756606AbYHASZ5 (ORCPT ); Fri, 1 Aug 2008 14:25:57 -0400 Received: (majordomo@vger.kernel.org) by vger.kernel.org id S1751658AbYHASZu (ORCPT ); Fri, 1 Aug 2008 14:25:50 -0400 Received: from mummy.ncsc.mil ([144.51.88.129]:39336 "EHLO mummy.ncsc.mil" rhost-flags-OK-OK-OK-OK) by vger.kernel.org with ESMTP id S1750897AbYHASZt (ORCPT ); Fri, 1 Aug 2008 14:25:49 -0400 Subject: Re: 2.6.27-rc1 + selinux new options = no httpd From: Stephen Smalley To: Eric Paris Cc: Gene Heskett , James Morris , linux-kernel@vger.kernel.org, Alexander Viro In-Reply-To: <1217515455.2902.94.camel@localhost.localdomain> References: <200807302254.26036.gene.heskett@gmail.com> <200807310909.27619.gene.heskett@gmail.com> <1217515455.2902.94.camel@localhost.localdomain> Content-Type: text/plain Organization: National Security Agency Date: Thu, 31 Jul 2008 13:47:53 -0400 Message-Id: <1217526473.20373.250.camel@moss-spartans.epoch.ncsc.mil> Mime-Version: 1.0 X-Mailer: Evolution 2.12.3 (2.12.3-5.fc8) Content-Transfer-Encoding: 7bit Sender: linux-kernel-owner@vger.kernel.org List-ID: X-Mailing-List: linux-kernel@vger.kernel.org Content-Length: 1125 Lines: 32 On Thu, 2008-07-31 at 10:44 -0400, Eric Paris wrote: > On Thu, 2008-07-31 at 09:09 -0400, Gene Heskett wrote: > > On Thursday 31 July 2008, James Morris wrote: > > > >What AVC messages are you seeing? > > > > I posted the whole screen from setroubleshoot earlier. > > I'm sorry but I can't seem to find it in your original message... > > http://marc.info/?l=linux-kernel&m=121747333012971&w=2 > > Do you have another pointer? I can't think of anything that went into > 2.6.27 related to SELinux that should have in any way changed file > access checks but I'll poke through the changelog and see if something > stands out... I suspect it is the append bug introduced by the vfs changes, fixed by http://marc.info/?l=linux-kernel&m=121726661110266&w=2 httpd would only be allowed append permission to its log file by policy. -- Stephen Smalley National Security Agency -- To unsubscribe from this list: send the line "unsubscribe linux-kernel" in the body of a message to majordomo@vger.kernel.org More majordomo info at http://vger.kernel.org/majordomo-info.html Please read the FAQ at http://www.tux.org/lkml/