Login
[x]
Log in using an account from:
Fedora Account System
Red Hat Associate
Red Hat Customer
Or login using a Red Hat Bugzilla account
Forgot Password
Login:
Hide Forgot
Create an Account
Red Hat Bugzilla – Attachment 678874 Details for
Bug 895610
Deja-dup cannot execute gpg
[?]
New
Simple Search
Advanced Search
My Links
Browse
Requests
Reports
Current State
Search
Tabular reports
Graphical reports
Duplicates
Other Reports
User Changes
Plotly Reports
Bug Status
Bug Severity
Non-Defaults
|
Product Dashboard
Help
Page Help!
Bug Writing Guidelines
What's new
Browser Support Policy
5.0.4.rh83 Release notes
FAQ
Guides index
User guide
Web Services
Contact
Legal
This site requires JavaScript to be enabled to function correctly, please enable it.
AVC2
selinux-deja-dup-2.txt (text/plain), 2.96 KB, created by
Ruslan Sagitov
on 2013-01-15 16:24:10 UTC
(
hide
)
Description:
AVC2
Filename:
MIME Type:
Creator:
Ruslan Sagitov
Created:
2013-01-15 16:24:10 UTC
Size:
2.96 KB
patch
obsolete
>SELinux is preventing /usr/bin/gpg from write access on the file /home/user/.cache/deja-dup/1463af8dcef0b6b3cc2eb4826bd73b82/duplicity-_K4iZu-tempdir/mktemp-i3M5JC-1. > >***** Plugin leaks (86.2 confidence) suggests ****************************** > >If you want to ignore gpg trying to write access the mktemp-i3M5JC-1 file, because you believe it should not need this access. >Then you should report this as a bug. >You can generate a local policy module to dontaudit this access. >Do ># grep /usr/bin/gpg /var/log/audit/audit.log | audit2allow -D -M mypol ># semodule -i mypol.pp > >***** Plugin catchall (14.7 confidence) suggests *************************** > >If you believe that gpg should be allowed write access on the mktemp-i3M5JC-1 file by default. >Then you should report this as a bug. >You can generate a local policy module to allow this access. >Do >allow this access for now by executing: ># grep gpg /var/log/audit/audit.log | audit2allow -M mypol ># semodule -i mypol.pp > >Additional Information: >Source Context staff_u:staff_r:gpg_t:s0-s0:c0.c1023 >Target Context staff_u:object_r:cache_home_t:s0 >Target Objects /home/user/.cache/deja- > dup/1463af8dcef0b6b3cc2eb4826bd73b82/duplicity- > _K4iZu-tempdir/mktemp-i3M5JC-1 [ file ] >Source gpg >Source Path /usr/bin/gpg >Port <Unknown> >Host >Source RPM Packages gnupg-1.4.12-1.fc17.i686 >Target RPM Packages >Policy RPM selinux-policy-3.10.0-166.fc17.noarch >Selinux Enabled True >Policy Type targeted >Enforcing Mode Enforcing >Host Name >Platform Linux 3.6.11-1.fc17.i686 #1 SMP Mon Dec 17 > 22:52:59 UTC 2012 i686 i686 >Alert Count 2 >First Seen 2013-01-15 19:53:29 MSK >Last Seen 2013-01-15 19:53:37 MSK >Local ID d342c758-a7f3-4272-bae2-731c450539d0 > >Raw Audit Messages >type=AVC msg=audit(1358265217.730:160): avc: denied { write } for pid=2827 comm="gpg" path="/home/user/.cache/deja-dup/1463af8dcef0b6b3cc2eb4826bd73b82/duplicity-_K4iZu-tempdir/mktemp-i3M5JC-1" dev="sda5" ino=10617244 scontext=staff_u:staff_r:gpg_t:s0-s0:c0.c1023 tcontext=staff_u:object_r:cache_home_t:s0 tclass=file > > >type=SYSCALL msg=audit(1358265217.730:160): arch=i386 syscall=execve success=yes exit=0 a0=9bd64e0 a1=9a238b0 a2=9850810 a3=9a238e0 items=0 ppid=2726 pid=2827 auid=1000 uid=1000 gid=1000 euid=1000 suid=1000 fsuid=1000 egid=1000 sgid=1000 fsgid=1000 tty=(none) ses=2 comm=gpg exe=/usr/bin/gpg subj=staff_u:staff_r:gpg_t:s0-s0:c0.c1023 key=(null) > >Hash: gpg,gpg_t,cache_home_t,file,write > >audit2allow > >#============= gpg_t ============== >allow gpg_t cache_home_t:file write; > >audit2allow -R > >#============= gpg_t ============== >allow gpg_t cache_home_t:file write; > >
You cannot view the attachment while viewing its details because your browser does not support IFRAMEs.
View the attachment on a separate page
.
View Attachment As Raw
Actions:
View
Attachments on
bug 895610
:
678873
| 678874