All of lore.kernel.org
 help / color / mirror / Atom feed
From: Stephen Smalley <sds@tycho.nsa.gov>
To: Jay Corrales <jscorrales1122@gmail.com>
Cc: SELinux@tycho.nsa.gov
Subject: Re: /bin/bash: Bad interpreter: Permission denied.
Date: Wed, 18 Dec 2013 16:52:15 -0500	[thread overview]
Message-ID: <52B2190F.1020100@tycho.nsa.gov> (raw)
In-Reply-To: <CACVacMszVX7Yuv1rcuzphQ2YXXCABMb2aQ1CY3zcoaiNmoqHYw@mail.gmail.com>

On 12/18/2013 04:46 PM, Jay Corrales wrote:
> ls -Z shows system_u:object_r:awips_exec_t. If execute_no_trans allow
> is add, it does not run in the awips_exec_t domain, but in user_t.

Um, what is the file mode, i.e. is it executable?

> 
> On 12/18/13, Stephen Smalley <sds@tycho.nsa.gov> wrote:
>> On 12/17/2013 11:23 AM, Jay Corrales wrote:
>>> Folks,
>>>
>>> We're running RedHat Enterprise Linux 5 (rhel5) with selinux strict and
>>> enforcing mode, and finding that something in our configuration prevents
>>> a
>>> simple shell script from domain transitioning from user_t to awips_t
>>> context. If we run a test virtual machine with a new install of rhel5, it
>>> does run OK, but something in our current configuration prevents this
>>> result. Wondering if it makes sense to run a tool like apol to find any
>>> clues as to why? The audit log (/var/log/audit/audit.log) shows an AVC
>>> requiring execute_no_trans for user_t (no listed here).
>>
>> Here you say you have a execute_no_trans denial.
>>
>>> [root@localhost ~]# sesearch -a -s user_t -t awips_exec_t -c file -p
>>> execute
>>
>> Here you search for execute permission.
>>
>> They are different.
>>
>> Also, what does ls -Z show for the script?
>>
>>
>>
> 
> 

  reply	other threads:[~2013-12-18 21:52 UTC|newest]

Thread overview: 13+ messages / expand[flat|nested]  mbox.gz  Atom feed  top
2013-12-17 16:23 /bin/bash: Bad interpreter: Permission denied Jay Corrales
2013-12-17 16:35 ` Stephen Smalley
2013-12-17 18:03   ` Jay Corrales
2013-12-17 18:15     ` Stephen Smalley
     [not found]       ` <CACVacMu4EvcdZzLVbBRFUvgg_RA0Mc7awZ0x_mzoxadmO6TSkw@mail.gmail.com>
2013-12-18 15:32         ` Jay Corrales
2013-12-18 17:55           ` Stephen Smalley
2013-12-18 21:53             ` Jay Corrales
2013-12-18 22:02               ` Stephen Smalley
2013-12-19  4:39                 ` Jay Corrales
2013-12-18 20:14 ` Stephen Smalley
2013-12-18 21:46   ` Jay Corrales
2013-12-18 21:52     ` Stephen Smalley [this message]
2013-12-18 21:55       ` Jay Corrales

Reply instructions:

You may reply publicly to this message via plain-text email
using any one of the following methods:

* Save the following mbox file, import it into your mail client,
  and reply-to-all from there: mbox

  Avoid top-posting and favor interleaved quoting:
  https://en.wikipedia.org/wiki/Posting_style#Interleaved_style

* Reply using the --to, --cc, and --in-reply-to
  switches of git-send-email(1):

  git send-email \
    --in-reply-to=52B2190F.1020100@tycho.nsa.gov \
    --to=sds@tycho.nsa.gov \
    --cc=SELinux@tycho.nsa.gov \
    --cc=jscorrales1122@gmail.com \
    /path/to/YOUR_REPLY

  https://kernel.org/pub/software/scm/git/docs/git-send-email.html

* If your mail client supports setting the In-Reply-To header
  via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line before the message body.
This is an external index of several public inboxes,
see mirroring instructions on how to clone and mirror
all data and code used by this external index.