All of lore.kernel.org
 help / color / mirror / Atom feed
* need advice for ld_so_cache_t errors
@ 2004-10-01 23:35 Greg Norris
  2004-10-02  0:59 ` Russell Coker
  2004-10-02  3:09 ` Russell Coker
  0 siblings, 2 replies; 15+ messages in thread
From: Greg Norris @ 2004-10-01 23:35 UTC (permalink / raw)
  To: SE-Linux

[-- Attachment #1: Type: text/plain, Size: 1200 bytes --]

OK, I've finally reached a point where I'm switching my system from
permissive to enforcing mode (and there was much rejoicing! ;-).  Things
seem to be working pretty well, but I'm noticing a number of
ld_so_cache_t errors logged...  in particular, restarting postfix causes
an absolute FLOOD of messages such as the one below (reformatted for my
own sanity).

   Oct  1 17:16:34 sasami kernel: audit(1096668994.071:0): avc:
     denied  { execute } for  pid=3039 path=/etc/ld.so.cache
     dev=hda5 ino=1022 scontext=system_u:system_r:postfix_master_t 
     tcontext=system_u:object_r:ld_so_cache_t tclass=file

This happens for a number of other domains as well, but postfix seems to
have an exceptional affinity.  Should I just go ahead and grant execute
privileges to all the various domains (it seems like this would be a
pain to manage)?  If not, what's the preferred way of squashing these
messages?  I've browsed through CVS, but didn't notice any policy
updates which would obviously affect this issue.


The system in question is an old Pentium II box running Debian sid, with 
the SELinux packages from Russell Coker's repository.  The kernel 
version is 2.6.9-rc3.

[-- Attachment #2: Digital signature --]
[-- Type: application/pgp-signature, Size: 189 bytes --]

^ permalink raw reply	[flat|nested] 15+ messages in thread

end of thread, other threads:[~2004-10-12 13:44 UTC | newest]

Thread overview: 15+ messages (download: mbox.gz follow: Atom feed
-- links below jump to the message on this page --
2004-10-01 23:35 need advice for ld_so_cache_t errors Greg Norris
2004-10-02  0:59 ` Russell Coker
2004-10-02  1:26   ` Greg Norris
2004-10-02  3:09 ` Russell Coker
2004-10-02  4:37   ` Greg Norris
2004-10-02 16:50     ` Greg Norris
2004-10-03 15:08       ` Russell Coker
2004-10-04  1:48         ` Greg Norris
2004-10-05  0:30           ` Greg Norris
2004-10-05  1:00             ` Greg Norris
2004-10-05  3:45               ` Tom London
2004-10-05 21:51                 ` Greg Norris
2004-10-08 15:42               ` Stephen Smalley
2004-10-08 21:02                 ` Daniel J Walsh
2004-10-12 13:39                   ` Stephen Smalley

This is an external index of several public inboxes,
see mirroring instructions on how to clone and mirror
all data and code used by this external index.