Re: Livecd-creator is disabling selinux

2014-01-14 Thread Daniel J Walsh
-BEGIN PGP SIGNED MESSAGE- Hash: SHA1 On 01/13/2014 04:17 PM, Richard W.M. Jones wrote: [Moving this to the libguestfs mailing list] On Mon, Jan 13, 2014 at 03:05:14PM -0500, Daniel J Walsh wrote: -BEGIN PGP SIGNED MESSAGE- Hash: SHA1 On 01/13/2014 11:49 AM, Richard W.M.

Re: Livecd-creator is disabling selinux

2014-01-13 Thread Daniel J Walsh
Gilmore wrote: El Fri, 10 Jan 2014 15:26:38 -0800 Adam Williamson awill...@redhat.com escribió: On Thu, 2014-01-09 at 11:32 +0100, Maros Zatko wrote: Dear guys and ladies, So it seems like livecd-creator is silently disabling selinux. Proof: vim $(which livecd-creator) ; line 150 Fact, that it's re

Re: Livecd-creator is disabling selinux

2014-01-13 Thread Richard W.M. Jones
On Mon, Jan 13, 2014 at 10:20:22AM -0500, Daniel J Walsh wrote: Secondly we prevent even unconfined_t from putting down labels on the file system that the kernel does not understand. IE If I am building a F21 image on a RHEL6 box, it would blow up in enforcing mode if run as unconfined_t. We

Re: Livecd-creator is disabling selinux

2014-01-13 Thread Daniel J Walsh
-BEGIN PGP SIGNED MESSAGE- Hash: SHA1 On 01/13/2014 11:49 AM, Richard W.M. Jones wrote: On Mon, Jan 13, 2014 at 10:20:22AM -0500, Daniel J Walsh wrote: Secondly we prevent even unconfined_t from putting down labels on the file system that the kernel does not understand. IE If I am

Re: Livecd-creator is disabling selinux

2014-01-13 Thread Richard W.M. Jones
[Moving this to the libguestfs mailing list] On Mon, Jan 13, 2014 at 03:05:14PM -0500, Daniel J Walsh wrote: -BEGIN PGP SIGNED MESSAGE- Hash: SHA1 On 01/13/2014 11:49 AM, Richard W.M. Jones wrote: On Mon, Jan 13, 2014 at 10:20:22AM -0500, Daniel J Walsh wrote: Secondly we prevent

Re: Livecd-creator is disabling selinux

2014-01-10 Thread Adam Williamson
On Thu, 2014-01-09 at 11:32 +0100, Maros Zatko wrote: Dear guys and ladies, So it seems like livecd-creator is silently disabling selinux. Proof: vim $(which livecd-creator) ; line 150 Fact, that it's re-enabled afterwards doesn't ease silent disablement of security feature. I'd love

Re: Livecd-creator is disabling selinux

2014-01-10 Thread Dennis Gilmore
-BEGIN PGP SIGNED MESSAGE- Hash: SHA1 El Fri, 10 Jan 2014 15:26:38 -0800 Adam Williamson awill...@redhat.com escribió: On Thu, 2014-01-09 at 11:32 +0100, Maros Zatko wrote: Dear guys and ladies, So it seems like livecd-creator is silently disabling selinux. Proof: vim $(which

Re: Livecd-creator is disabling selinux

2014-01-10 Thread Adam Williamson
On Fri, 2014-01-10 at 17:33 -0600, Dennis Gilmore wrote: El Fri, 10 Jan 2014 15:26:38 -0800 Adam Williamson awill...@redhat.com escribió: On Thu, 2014-01-09 at 11:32 +0100, Maros Zatko wrote: Dear guys and ladies, So it seems like livecd-creator is silently disabling selinux. Proof

Re: Livecd-creator is disabling selinux

2014-01-10 Thread Tim Flink
and ladies, So it seems like livecd-creator is silently disabling selinux. Proof: vim $(which livecd-creator) ; line 150 Fact, that it's re-enabled afterwards doesn't ease silent disablement of security feature. I'd love to know the reason and if it's possible to do something

Re: Livecd-creator is disabling selinux

2014-01-10 Thread Dennis Gilmore
Adam Williamson awill...@redhat.com escribió: On Thu, 2014-01-09 at 11:32 +0100, Maros Zatko wrote: Dear guys and ladies, So it seems like livecd-creator is silently disabling selinux. Proof: vim $(which livecd-creator) ; line 150 Fact, that it's re-enabled afterwards

Livecd-creator is disabling selinux

2014-01-09 Thread Maros Zatko
Dear guys and ladies, So it seems like livecd-creator is silently disabling selinux. Proof: vim $(which livecd-creator) ; line 150 Fact, that it's re-enabled afterwards doesn't ease silent disablement of security feature. I'd love to know the reason and if it's possible to do something about

Re: Livecd-creator is disabling selinux

2014-01-09 Thread Daniel J Walsh
-BEGIN PGP SIGNED MESSAGE- Hash: SHA1 On 01/09/2014 05:32 AM, Maros Zatko wrote: Dear guys and ladies, So it seems like livecd-creator is silently disabling selinux. Proof: vim $(which livecd-creator) ; line 150 Fact, that it's re-enabled afterwards doesn't ease silent disablement