Please take our Survey
logo       

Choosing A Webhost:
A web hosting service is a type of Internet hosting service that allows individuals and organizations to provide their own website accessible via the World Wide Web. Web hosts are companies that provide space on a server they own for use by their clients as well as providing Internet connectivity, typically in a data center. Web hosts can also provide data center space and connectivity to the Internet for servers they do not own to be located in their data center, called colocation. more...

Re: new kernel, new policy installed as .rpmnew: msg#00270

Subject: Re: new kernel, new policy installed as .rpmnew
On Wed, 2004-12-29 at 21:42 -0500, Charles R. Anderson wrote:
> I just yum updated, and got the latest testing kernel and policy 
> files:
> 
>   Install: kernel.i686 0:2.6.9-1.715_FC3
>   Install: kernel-smp.i686 0:2.6.9-1.715_FC3
> [...]
>  Update: selinux-policy-targeted.noarch 0:1.17.30-2.58
>  Update: selinux-policy-targeted-sources.noarch 0:1.17.30-2.58
> [...]
> Installing: kernel-smp 100 % done 1/160 
> warning: /etc/selinux/targeted/contexts/files/file_contexts created as 
> /etc/selinux/targeted/contexts/files/file_contexts.rpmnew
> warning: /etc/selinux/targeted/policy/policy.18 created as 
> /etc/selinux/targeted/policy/policy.18.rpmnew
> Updating: selinux-policy-targeted 100 % done 2/160 
> 
> The FAQ says that the policy reloads automatically, and that a manual
> relabel may be necessary.  It doesn't say anything about fixing the
> filenames that were named .rpmnew.  How can the policy automatically
> reload when the file isn't named correctly?

This can happen when you have selinux-policy-targeted-sources installed.
It's complicated to solve; I think we ended up deciding that if you have
-sources installed, it's up to you to do a policy rebuild for new
versions.

> Since policy is tied to the kernel, what happens when I have more than
> one kernel installed, and I boot an older one from grub? 

If you don't need to customize policy, deinstall the -sources package,
and move the .rpmnew files over the non-.rpmnew versions.  Then this
problem goes away.

If you do need to customize policy, then you're probably best off
booting in non-enforcing mode after an update to test and ensure that
your changes work with the latest package.  Keeping a custom policy is
nontrivial at the moment, and it's something I'd like to fix.




<Prev in Thread] Current Thread [Next in Thread>
Google Custom Search

Recently Viewed:
qnx.openqnx.dev...    gcc.libstdc++.c...    solaris.opensol...    information-ret...    misc.misterhous...    web.catalyst.ge...    apache.webservi...    redhat.release....    hardware.lirc/2...    kernel.autofs/2...    technology.sust...    linux.vdr/2003-...    editors.lyx.gen...    org.user-groups...    netbsd.devel.pk...    xdg.devel/2004-...    version-control...    jakarta.slide.d...    debian.packages...    creativecommons...    ports.ppc.embed...    bug-tracking.bu...   
Home | blog view | USPTO Patent Archive | advertise | OSDir is an inevitable website. super tiny logo

Free Magazines

Cisco News
Receive a free quarterly e-newsletter with exclusive articles on how Cisco IT uses its own products and solutions to enable the business.
subscribe

Systems Management News, the newspaper for IT systems administration and data center managers! Each issue of Systems Management News is chock-full of news and analysis to help you understand what's happening in your field.
subscribe

The Enterprise Newsweekly eWeek is the essential technology information source for builders of e-business.
subscribe

Oracle Magazine Oracle Magazine contains technology strategy articles, sample code, tips, Oracle and partner news, how to articles for developers and DBAs, and more. Oracle (NASDAQ: ORCL) is the world's largest enterprise software company.
subscribe

Total Telecom Total Telecom is "The Economist of the communications industry".
subscribe