When the SELinux module is in permissive mode, a bug in the convert_contexts function used by the load_policy function can leave the SID table in an inconsistent state when users, roles, or types are removed from the policy on a running system. The attached patch fixes this bug. To apply, save the attached patch to ~/services.patch, cd selinux, and run 'patch -p1 < services.patch'. Then, rebuild the LSM-patched kernel with the built-in SELinux security module.
-- Stephen D. Smalley, NAI Labs ssmalley@nai.com-- You have received this message because you are subscribed to the selinux list. If you no longer wish to subscribe, send mail to majordomo@tycho.nsa.gov with the words "unsubscribe selinux" without quotes as the message.
- TEXT/PLAIN attachment: services.patch
This archive was generated by hypermail 2.2.0 on Wed 11 Jun 2008 - 08:10:54 EDT