[rsbac] Re: RC model not working in linux-2.6.3 v1.2.3 ?

Thomas Mueller news-exp-jun04 at tmueller.com
Sun Mar 14 11:58:47 CET 2004


On Sat, 13 Mar 2004 20:01:25 +0100 Amon Ott wrote:

>> RC seems not to be compiled in? But it should be I think:
>> 
>> $ cat config-2.6.3-586 |grep ^CONFIG_RSBAC
[..]
>> CONFIG_RSBAC_RC=y
>> CONFIG_RSBAC_RC_AUTH_PROT=y
>> CONFIG_RSBAC_RC_GEN_PROT=y
>> CONFIG_RSBAC_RC_BACKUP=y
>> CONFIG_RSBAC_RC_NET_DEV_PROT=y
>> CONFIG_RSBAC_RC_NET_OBJ_PROT=y
>> CONFIG_RSBAC_RC_NR_P_LISTS=4
[..]
> 
> Weird. Strange. How can it be both enabled and disabled? Needless to say 
> that it compiles correctly here.

Yes of course.

> Did you recheck with make menuconfig and after a make clean? Does any file 
> *rc* appear in /proc/rsbac-info? Do you see a rsbac/adf/rc/rc_main.o file?

Yes I rechecked everything twice. There is no *rc* file in
/proc/rsbac-info/, but rc_main.o exists yes.

I did some more tests and compiled more modules to see if that happens
with other modules too. I added FF RC AUTH ACL CAP and that worked fine,
all of them are in now:
$ cat /proc/rsbac-info/stats
RSBAC Status
------------
RSBAC Version: v1.2.3-pre4
Compiled Modules: FF RC AUTH ACL CAP

I think I found another problem. rsbac_rc_role_menu -> Type Comp FD -> Set
Read* doesn't change anything, the others seems to be okay.

My last problem is probably my fault: I want to add ADD_TO_KERNEL to one
role and remove it from every other, but I can't find that anywhere. Could
you please give me a hint where that is hidden? Thanks!


Thomas
-- 
http://www.tmueller.com for pgp key (95702B3B)



More information about the rsbac mailing list