All of lore.kernel.org
 help / color / mirror / Atom feed
* Restorecond and .xsession-errors
@ 2010-05-12 19:10 Alan Rouse
  2010-05-12 20:44 ` Dominick Grift
  0 siblings, 1 reply; 3+ messages in thread
From: Alan Rouse @ 2010-05-12 19:10 UTC (permalink / raw)
  To: selinux@tycho.nsa.gov

[-- Attachment #1: Type: text/plain, Size: 874 bytes --]

I'm down to one AVC left booting to a desktop in OpenSUSE 11.3 milestone 6.

type=AVC msg=audit(127369094.093:8): avc: denied { relabelfrom } for pid=3089 comm="restorecond" name=".xsession-errors" dev=sda3 ino=127759 scontext=user_u:user_r:user_t:s0 tcontext=system_u:object_r:xauth_home_t:s0 tclass=file

It looks to me like somewhere late in the boot, a windowing error occurs and it attempts to log it to .xsession-errors.  For some reason at that point in time it attempts to relabel that file and is denied.

The file context on .xsession-errors in the unprivileged user's home directory is user_u:object_r:user_home_t:s0

However, when I run audit2allow on that avc, it says "This avc is a constraint violation.  You will need to add an attribute to either the source or target type to make it work."

Should I relabel .xsession-errors?  If so, to what?


[-- Attachment #2: Type: text/html, Size: 1488 bytes --]

^ permalink raw reply	[flat|nested] 3+ messages in thread

end of thread, other threads:[~2010-05-12 20:51 UTC | newest]

Thread overview: 3+ messages (download: mbox.gz follow: Atom feed
-- links below jump to the message on this page --
2010-05-12 19:10 Restorecond and .xsession-errors Alan Rouse
2010-05-12 20:44 ` Dominick Grift
2010-05-12 20:51   ` Dominick Grift

This is an external index of several public inboxes,
see mirroring instructions on how to clone and mirror
all data and code used by this external index.