Bug#756731: [DSE-Dev] Bug#756731: selinux-policy-default: Setting SELinux to enforce when using systemd some AVCs are logged during boot

2014-08-05 Thread Andreas Florath
Hello! As suggested, I retested this with Jessie: There are still some AVCs logged, but these differ from the ones logged in Wheezy. Aug 5 09:26:11 debselinux01 kernel: [1.197831] audit: type=1400 audit(1407223571.360:4): avc: denied { net_admin } for pid=166 comm=systemd-tmpfile

Bug#756731: [DSE-Dev] Bug#756731: selinux-policy-default: Setting SELinux to enforce when using systemd some AVCs are logged during boot

2014-08-01 Thread Mika Pflüger
Hi Andre, as you can see I set the severity of the cosmetic bug reports, where AVCs are logged but apparently no functional degradation happens to minor. Often programs will use different codepaths (or do not actually care) when something is denied (think of the equivalent of ls -la|grep etc [or

Bug#756731: [DSE-Dev] Bug#756731: selinux-policy-default: Setting SELinux to enforce when using systemd some AVCs are logged during boot

2014-08-01 Thread Andreas Florath
Hello Mika, thank you very much for your detailed explanation. Looks that I miss some basics here. I'll try to reproduce the bugs I found with Jessie. (It might take some time, because I start vacation in the next days...) Thanks for your offer about the VMs - but I am able to setup a VM on my