All of lore.kernel.org
 help / color / mirror / Atom feed
From: Dominick Grift <domg472@gmail.com>
To: Alan Rouse <alan.rouse@ericsson.com>
Cc: "'selinux@tycho.nsa.gov'" <selinux@tycho.nsa.gov>
Subject: Re: SELinux Policy in OpenSUSE 11.2
Date: Tue, 16 Feb 2010 16:22:29 +0100	[thread overview]
Message-ID: <4B7AB835.5080008@gmail.com> (raw)
In-Reply-To: <5A5E55DF96F73844AF7DFB0F48721F0F529A558532@EUSAACMS0703.eamcs.ericsson.se>

[-- Attachment #1: Type: text/plain, Size: 2285 bytes --]

On 02/16/2010 03:55 PM, Alan Rouse wrote:
le
> type=AVC msg=audit(1265904613.689:203): avc:  denied  { execstack } for  pid=2382 comm="cupsd" scontext=system_u:system_r:sysadm_t tcontext=system_u:system_r:sysadm_t tclass=process
> type=AVC msg=audit(1265904613.690:204): avc:  denied  { execmem } for  pid=2382 comm="cupsd" scontext=system_u:system_r:sysadm_t tcontext=system_u:system_r:sysadm_t tclass=process
> type=AVC msg=audit(1265904614.260:205): avc:  denied  { read write } for  pid=2448 comm="smartd" name="sda" dev=tmpfs ino=1749 scontext=system_u:system_r:sysadm_t tcontext=system_u:object_r:fixed_disk_device_t tclass=blk_file
> type=AVC msg=audit(1265904614.260:206): avc:  denied  { open } for  pid=2448 comm="smartd" name="sda" dev=tmpfs ino=1749 scontext=system_u:system_r:sysadm_t tcontext=system_u:object_r:fixed_disk_device_t tclass=blk_file
> type=AVC msg=audit(1265904614.261:207): avc:  denied  { ioctl } for  pid=2448 comm="smartd" path="/dev/sda" dev=tmpfs ino=1749 scontext=system_u:system_r:sysadm_t tcontext=system_u:object_r:fixed_disk_device_t tclass=blk_file
> type=AVC msg=audit(1265904615.964:209): avc:  denied  { read } for  pid=2337 comm="auditd" scontext=system_u:system_r:sysadm_t tcontext=system_u:system_r:sysadm_t tclass=netlink_audit_socket
> type=AVC msg=audit(1265904616.063:212): avc:  denied  { read } for  pid=308 comm="udevd" scontext=system_u:system_r:sysadm_t tcontext=system_u:system_r:sysadm_t tclass=netlink_kobject_uevent_socket
> type=AVC msg=audit(1265904616.063:213): avc:  denied  { write } for  pid=308 comm="udevd" scontext=system_u:system_r:sysadm_t tcontext=system_u:system_r:sysadm_t tclass=netlink_kobject_uevent_socket

With regard to the AVC denials above it seems that these services
(cupsd, smartd, auditd and udevd) run in the wrong domain. When you
restart services manually, you should use "run_init".

run_init /etc/rc.d/init.d/cupsd start

Besides that some if this might still not work. For example execstack
and execmem permissions for cupsd, but start by executing these daemons
in the proper domains first.

As for dbus i have not noticed any dbus specific AVC denials. It may be
the dbus denials are directed to /var/log/messages,
/var/log/audit/audit.log or dmesg.

> 
> 
> 



[-- Attachment #2: OpenPGP digital signature --]
[-- Type: application/pgp-signature, Size: 261 bytes --]

  reply	other threads:[~2010-02-16 15:22 UTC|newest]

Thread overview: 113+ messages / expand[flat|nested]  mbox.gz  Atom feed  top
2010-02-16 14:55 SELinux Policy in OpenSUSE 11.2 Alan Rouse
2010-02-16 15:22 ` Dominick Grift [this message]
2010-02-16 18:04   ` Alan Rouse
2010-02-16 18:35     ` Dominick Grift
2010-02-16 18:52     ` Dominick Grift
2010-02-16 19:28     ` Stephen Smalley
2010-02-16 20:06       ` Justin P. mattock
2010-02-16 19:10 ` Stephen Smalley
2010-02-16 19:19   ` Alan Rouse
2010-02-16 19:38     ` Stephen Smalley
2010-02-16 21:30       ` Alan Rouse
2010-02-16 22:52         ` Dominick Grift
2010-02-17  3:36           ` Justin P. mattock
2010-02-17  7:16           ` Justin P. mattock
2010-02-17 13:43             ` Stephen Smalley
2010-02-17 15:35               ` Justin P. mattock
2010-02-17 16:34             ` Alan Rouse
2010-02-17 16:58               ` Stephen Smalley
2010-02-17 18:34                 ` Alan Rouse
2010-02-17 18:50                   ` Justin P. mattock
2010-02-17 18:58                   ` Stephen Smalley
2010-02-17 19:39                     ` Alan Rouse
2010-02-17 19:47                     ` Justin P. mattock
2010-02-17 20:00                       ` Stephen Smalley
2010-02-17 20:03                         ` Alan Rouse
2010-02-17 20:12                           ` Dominick Grift
2010-02-17 20:18                           ` Stephen Smalley
2010-02-17 20:17                             ` Alan Rouse
2010-02-17 20:25                             ` Stephen Smalley
     [not found]                               ` <5A5E55DF96F73844AF7DFB0F48721F0F529A7802A0@EUSAACMS0703.eamcs.ericsson.se>
     [not found]                                 ` <1266438910.4945.137.camel@moss-pluto.epoch.ncsc.mil>
2010-02-17 20:49                                   ` Alan Rouse
2010-02-17 21:09                                     ` Stephen Smalley
2010-02-17 21:11                                       ` Alan Rouse
2010-02-17 21:29                                         ` Stephen Smalley
2010-02-17 21:37                                           ` Stephen Smalley
2010-02-17 21:48                                             ` Alan Rouse
2010-02-18 14:16                                               ` Stephen Smalley
2010-02-18 21:28                                                 ` Stephen Smalley
2010-02-18 16:03                                               ` Stephen Smalley
2010-02-18 17:36                                                 ` Alan Rouse
2010-02-18 17:53                                                   ` Stephen Smalley
2010-02-18 18:21                                                     ` Alan Rouse
2010-02-19 14:49                                                       ` Stephen Smalley
2010-02-19 15:29                                                         ` Alan Rouse
2010-02-19 17:46                                                           ` Stephen Smalley
2010-02-19 20:23                                                             ` Alan Rouse
2010-02-19 21:06                                                               ` Stephen Smalley
2010-02-19 21:10                                                                 ` Alan Rouse
     [not found]                                           ` <5A5E55DF96F73844AF7DFB0F48721F0F529A780365@EUSAACMS0703.eamcs.ericsson.se>
2010-02-18 14:12                                             ` Stephen Smalley
2010-02-18 14:45                                               ` Alan Rouse
2010-02-17 20:08                         ` Alan Rouse
2010-02-18 21:40                           ` Justin P. mattock
2010-02-18 21:53                             ` Alan Rouse
2010-02-18 23:17                               ` Justin P. mattock
2010-02-19 14:35                                 ` Stephen Smalley
2010-02-19 15:43                                   ` Justin P. mattock
2010-02-19 15:58                                 ` Alan Rouse
2010-02-19 16:26                                   ` Justin P. mattock
2010-02-19 14:28                             ` Stephen Smalley
2010-02-19 15:48                               ` Justin P. mattock
2010-02-19 18:46                               ` Justin P. mattock
2010-02-19 21:08                                 ` Alan Rouse
2010-02-19 21:19                                   ` Dominick Grift
2010-02-19 21:22                                   ` Justin P. mattock
2010-02-19 21:25                                   ` Stephen Smalley
2010-02-19 21:30                                     ` Alan Rouse
2010-02-19 21:37                                       ` Stephen Smalley
2010-02-19 21:53                                         ` Alan Rouse
2010-02-22 14:10                                           ` Stephen Smalley
     [not found]                                             ` <5A5E55DF96F73844AF7DFB0F48721F0F52E41FF16B@EUSAACMS0703.eamcs.ericsson.se>
     [not found]                                               ` <1266850844.15933.38.camel@moss-pluto.epoch.ncsc.mil>
2010-02-22 17:39                                                 ` Alan Rouse
2010-02-22 17:56                                                   ` Stephen Smalley
2010-02-22 19:12                                                     ` Alan Rouse
2010-02-22 19:37                                                       ` Stephen Smalley
2010-02-19 23:48                                         ` Justin P. mattock
2010-02-22  1:29                                         ` Justin P. mattock
2010-02-19 21:47                                     ` Justin P. mattock
2010-02-22 14:00                                       ` Stephen Smalley
2010-02-22 19:27                                         ` Justin Mattock
     [not found]                                           ` <dd18b0c31002221129s4be9b56cha13b7be39c2cba36@mail.gmail.com>
2010-02-22 19:57                                             ` Justin P. mattock
2010-02-22 20:24                                               ` Stephen Smalley
2010-02-22 21:25                                                 ` Justin Mattock
2010-02-22 21:42                                                   ` Stephen Smalley
2010-02-22 22:10                                                   ` Justin P. mattock
2010-02-22 22:35                                                     ` Justin Mattock
2010-02-23  6:17                                                       ` Justin P. mattock
2010-02-23 13:40                                                         ` Stephen Smalley
2010-02-23 14:13                                                           ` Justin P. mattock
2010-02-23 15:56                                                           ` Alan Rouse
2010-02-23 16:10                                                             ` Stephen Smalley
2010-02-23 17:41                                                               ` Justin P. mattock
2010-02-23 18:01                                                                 ` Stephen Smalley
2010-02-23 18:30                                                                   ` Justin P. mattock
2010-02-23 18:42                                                                     ` Stephen Smalley
2010-02-23 18:58                                                                       ` Justin P. mattock
2010-02-23 19:00                                                                         ` Stephen Smalley
2010-02-23 19:03                                                                           ` Justin Mattock
2010-02-23 20:37                                                                             ` Justin P. mattock
2010-02-22 17:58                                       ` Alan Rouse
2010-02-22 18:23                                         ` Justin P. mattock
2010-02-22 18:31                                           ` Alan Rouse
2010-02-22 18:49                                             ` Justin P. mattock
     [not found]                     ` <5A5E55DF96F73844AF7DFB0F48721F0F529A780232@EUSAACMS0703.eamcs.ericsson.se>
2010-02-17 19:58                       ` Stephen Smalley
2010-02-17 20:09                         ` Justin P. mattock
2010-02-17 20:21                           ` Stephen Smalley
2010-02-17 23:22                             ` Justin P. mattock
2010-02-18 15:17                               ` Alan Rouse
2010-02-18 18:33                                 ` Justin P. mattock
2010-02-18 18:44                                   ` Alan Rouse
2010-02-17 13:35         ` Stephen Smalley
2010-02-17 15:14           ` Alan Rouse
2010-02-17 15:33             ` Stephen Smalley
  -- strict thread matches above, loose matches on Subject: below --
2010-02-17 14:04 Thomas
2010-04-29  6:43 Justin P. Mattock
2010-04-29  7:01 ` Justin P. Mattock

Reply instructions:

You may reply publicly to this message via plain-text email
using any one of the following methods:

* Save the following mbox file, import it into your mail client,
  and reply-to-all from there: mbox

  Avoid top-posting and favor interleaved quoting:
  https://en.wikipedia.org/wiki/Posting_style#Interleaved_style

* Reply using the --to, --cc, and --in-reply-to
  switches of git-send-email(1):

  git send-email \
    --in-reply-to=4B7AB835.5080008@gmail.com \
    --to=domg472@gmail.com \
    --cc=alan.rouse@ericsson.com \
    --cc=selinux@tycho.nsa.gov \
    /path/to/YOUR_REPLY

  https://kernel.org/pub/software/scm/git/docs/git-send-email.html

* If your mail client supports setting the In-Reply-To header
  via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line before the message body.
This is an external index of several public inboxes,
see mirroring instructions on how to clone and mirror
all data and code used by this external index.