Re: [Xen-devel] [Xen-users] XSM/Flask iomem

2018-09-27 Thread George Dunlap
[Moving to xen-devel] Daniel, Any comments on this one? -George On Wed, Sep 26, 2018 at 12:41 PM wrote: > > Hi, > > I just noticed from a bad behaviour of my installation and the > security_iterate_iomem_sids > function that the iomem ranges have to be sorted in the device_contexts file. > Th

Re: [Xen-devel] [Xen-users] XSM/Flask iomem

2018-09-28 Thread Daniel De Graaf
This is apparently a mismatch between what the checkpolicy compilation does and what it is expected to do. While some parts of checkpolicy do this sorting, the main compilation flow does not, and the policy compilation process does not ensure inputs are sorted. In the future, newer versions of c

Re: [Xen-devel] [Xen-users] XSM/Flask iomem

2018-10-01 Thread nicolas . poirot
Ok thanks. I didn't suspect checkpolicy to be in charge of this. I used the version 2.5 so far. -Daniel De Graaf a écrit : - A : nicolas.poi...@bertin.fr De : Daniel De Graaf Date : 28/09/2018 21:13 Cc : George Dunlap , xen-devel Objet : Re: [Xen-users] XSM/Flask iomem This is appare