Amon Ott | 2 Jun 2005 12:59

patch-2.4.31-v1.2.4 in pre

Hi,

the RSBAC 1.2.4 patch for kernel 2.4.31 is in pre dir for testing. 
Please try it and report any problems.

http://rsbac.org/download#pre

Amon.
--

-- 
http://www.rsbac.org - GnuPG: 2048g/5DEAAA30 2002-10-22
_______________________________________________
rsbac mailing list
rsbac <at> rsbac.org
http://www.rsbac.org/mailman/listinfo/rsbac
Amon Ott | 3 Jun 2005 08:40

Re: RSBAC and Linux distribution upgrades

On Dienstag 31 Mai 2005 09:42, Patrique Wolfrum wrote:
> In /proc/rsbac-info/stats_rc:
> 
> Role entry size is 52, 38 entries used
> Used type entries: fd: 63, dev: 4, ipc: 3, user: 3, process: 16, 
group:
> 1, netdev: 3, betemp: 3, netobj: 3
> 
> Looks good so far.

Ok.

> After upgrading the distribution, I first compiled the new kernel
> (prepatched kernel 2.6.11-rsbac-v1.2.4-20050412), then the 
rsbac-admintools.
> 
> To be on the safe side, I removed now each backup of the admin-tools 
or
> the libraries and also every older kernel-sources on the system
> (/usr/src/linux points to the new 2.6.11 kernel). Recompiling the
> admin-tools didn't bring an advancement though.
> 
> Now, the RSBAC-errormessage, that is for example shown when  trying 
to
> access "Type comp FD" in the RC-submenu of rsbac_admin, is:
> RSBAC_EINVALIDTARGET (or in other rsbac_admin options 
RSBAC_EINVALIDVALUE)

It would be great if I could have a look at your system myself, e.g. 
through SSH access.
(Continue reading)

Oliver Breuer | 3 Jun 2005 14:40
Picon

Re: Random "file not found" errors

here the problem occurs quite often. It occurs not only with virtual-fs. I even cannot compile a kernel
because it stops compiling already after a short time complaining about some random file not found. When
running under a non rsbac-kernel, the same compilation completes without errors.

Oliver

RSBAC Discussion and Announcements <rsbac <at> rsbac.org> schrieb am 03.06.05 14:33:24:

> I have already mentioned this on this list on January 21, 2005. 
> The problem continues on my boxes at random times and very seldom (a 
> couple of times a week). The only thing that I noticed it is that it has 
> to do always with some SYM-LINKS, independently if the file is protected
> with RC, FF or other modules. No clue of the reason, but something with 
> virtual-fs and RSBAC perhaps.
> 
> Andrea
> 
> 
> On Thu, May 12, 2005 at 02:56:07PM +0200, Oliver Breuer wrote:
> *  Hi all,
> * 
> * when using the 2.6.11-Kernel with RSBAC 1.2.4, at random times random
> * files are not found when trying to access them. But this occures only
> * at random times. The next try (just one second later), the file can be
> * accessed. There are no log messages generated from RSBAC.
> * 
> * After a lot of trying I found one reproducible case:
> * 
> * - tmpfs mounted on /sysmnt/shmtmp/shm
> *   -> unix-mode: rwxrwxrwt
(Continue reading)

Amon Ott | 3 Jun 2005 18:58

Re: Random "file not found" errors

On Freitag 03 Juni 2005 14:40, Oliver Breuer wrote:
> here the problem occurs quite often. It occurs not only with 
virtual-fs. I even cannot compile a kernel because it stops compiling 
already after a short time complaining about some random file not 
found. When running under a non rsbac-kernel, the same compilation 
completes without errors.

This is symlinks only, or files, too?

> RSBAC Discussion and Announcements <rsbac <at> rsbac.org> schrieb am 
03.06.05 14:33:24:
> 
> > I have already mentioned this on this list on January 21, 2005. 
> > The problem continues on my boxes at random times and very seldom 
(a 
> > couple of times a week). The only thing that I noticed it is that 
it has 
> > to do always with some SYM-LINKS, independently if the file is 
protected
> > with RC, FF or other modules. No clue of the reason, but something 
with 
> > virtual-fs and RSBAC perhaps.
> > 
> > Andrea
> > 
> > 
> > On Thu, May 12, 2005 at 02:56:07PM +0200, Oliver Breuer wrote:
> > *  Hi all,
> > * 
> > * when using the 2.6.11-Kernel with RSBAC 1.2.4, at random times 
(Continue reading)

Andrea Pasquinucci | 8 Jun 2005 09:36
Picon

new fedora rpms

The following updates have been uploaded to
http://fedora.rsbac.mprivacy-update.de/

  kernel-2.6.11.11-rsbac_v1.2.4_bf05_pax_soft.i686.rpm
  kernel-sourcecode-2.6.11.11-rsbac_v1.2.4_bf05_pax_soft.noarch.rpm

I have also updated rsbac-scripts-1.2.4-fc3.11.noarch.rpm. 

This kernel seems to be reasonably stable, except that for the random 
"file not found" errors. 

Andrea

--
Andrea Pasquinucci                     cesare <at> ucci.it
PGP key: http://www.ucci.it/ucci_pub_key.asc
fingerprint = 569B 37F6 45A4 1A17 E06F  CCBB CB51 2983 6494 0DA2
_______________________________________________
rsbac mailing list
rsbac <at> rsbac.org
http://www.rsbac.org/mailman/listinfo/rsbac
Andrea Pasquinucci | 8 Jun 2005 09:46
Picon

unresolved issues

I list a few issues that in my opinion/knowledge are not resolved

- kernel random "file not found" error

- missing links in http://www.rsbac.org/download/bugfixes to bugfix
  (i.e. where is the link to 1.2.4.bf5 ?) and to 
  http://download.rsbac.mprivacy-update.de/bugfixes/v1.2.4/

- I have not been able to use DAC GROUP control, if I compiled a kernel 
  with it (tried various times with different combinations of 
  parameters) access was not granted in some situations, or not checked 
  in others, so I have removed it from my kernels.

Andrea

--
Andrea Pasquinucci                     cesare <at> ucci.it
PGP key: http://www.ucci.it/ucci_pub_key.asc
fingerprint = 569B 37F6 45A4 1A17 E06F  CCBB CB51 2983 6494 0DA2
_______________________________________________
rsbac mailing list
rsbac <at> rsbac.org
http://www.rsbac.org/mailman/listinfo/rsbac
Amon Ott | 8 Jun 2005 14:13

Re: unresolved issues

On Mittwoch 08 Juni 2005 09:46, Andrea Pasquinucci wrote:
> - kernel random "file not found" error

We are hunting that bug now.

> - missing links in http://www.rsbac.org/download/bugfixes to bugfix
>   (i.e. where is the link to 1.2.4.bf5 ?) and to 
>   http://download.rsbac.mprivacy-update.de/bugfixes/v1.2.4/

Links added.

> - I have not been able to use DAC GROUP control, if I compiled a 
kernel 
>   with it (tried various times with different combinations of 
>   parameters) access was not granted in some situations, or not 
checked 
>   in others, so I have removed it from my kernels.

There have been some group control related smaller fixes. Can you 
please retest with latest svn code, or test with the upcoming 
1.2.5-pre1? You should use a test system or disable attribute writing 
to disk, because some lists are updated to a new version.

Thanks for the report!

Amon.
--

-- 
http://www.rsbac.org - GnuPG: 2048g/5DEAAA30 2002-10-22
Amon Ott | 8 Jun 2005 16:50

Re: Random "file not found" errors

On Donnerstag 12 Mai 2005 14:56, Oliver Breuer wrote:
> when using the 2.6.11-Kernel with RSBAC 1.2.4, at random times 
random files are not found when trying to access them. But this 
occures only at random times. The next try (just one second later), 
the file can be accessed. There are no log messages generated from 
RSBAC.

I have found the reason for this bug, but no bugfix yet. A workaround 
is to disable RSBAC symlink redirection in kernel config.

Amon.
--

-- 
http://www.rsbac.org - GnuPG: 2048g/5DEAAA30 2002-10-22
igraltist | 8 Jun 2005 19:02
Picon

net_temp

hallo liste
i have the follow problem.
i use the kernel 2.6.10 with the rsbac_admin_tool v1.2.3.
i do setup some nettemplate under the softmode then when i reboot in a
kernel with secmode then there is the nettemplate  are not visible.
in the rsbac_log i get this.
 request: READ ,pid xxx ,ppid xxx ,prog_name net_temp ,uid 400 , 
target_type NETTEMP , tid 0 attr none ,value 0 , result NOT GRANTED 
by RC.
i do now not to know how i can solve this.

then i have a second point this is not so important.
when i us the nvidia driver for the grafikcard then i can not use the glx
module because the x-server stop than. without the glx-module i can use it.

mfg 
igraltist

--

-- 
Weitersagen: GMX DSL-Flatrates mit Tempo-Garantie!
Ab 4,99 Euro/Monat: http://www.gmx.net/de/go/dsl
Amon Ott | 9 Jun 2005 17:33

RSBAC v1.2.5-pre1 released

Hi!

RSBAC v1.2.5-pre1 has been released for kernels 2.4.30-31 and 2.6.11. 
It contains many bugfixes since 1.2.4, many additional interceptions 
and improvements for easier use.

Please read the Upgrading document at 
http://rsbac.org/documentation:rsbac_handbook:upgrading before 
upgrading from 1.2.4.

Amon.
--

-- 
http://www.rsbac.org - GnuPG: 2048g/5DEAAA30 2002-10-22
_______________________________________________
rsbac mailing list
rsbac <at> rsbac.org
http://www.rsbac.org/mailman/listinfo/rsbac

Gmane