Bug 117758

Summary: Should X server have access to getattr on /var/run/xauth/foo?
Product: [Fedora] Fedora Reporter: Aleksey Nogin <aleksey>
Component: policyAssignee: Daniel Walsh <dwalsh>
Status: CLOSED RAWHIDE QA Contact:
Severity: medium Docs Contact:
Priority: medium    
Version: rawhideKeywords: SELinux
Target Milestone: ---   
Target Release: ---   
Hardware: All   
OS: Linux   
Whiteboard:
Fixed In Version: Doc Type: Bug Fix
Doc Text:
Story Points: ---
Clone Of: Environment:
Last Closed: 2004-04-07 02:03:58 UTC Type: ---
Regression: --- Mount Type: ---
Documentation: --- CRM:
Verified Versions: Category: ---
oVirt Team: --- RHEL 7.3 requirements from Atomic Host:
Cloudforms Team: --- Target Upstream Version:
Embargoed:

Description Aleksey Nogin 2004-03-08 10:07:25 UTC
I am seeing

avc:  denied  { getattr } for  pid=2567 exe=/usr/X11R6/bin/XFree86
path=/var/run/xauth/A:0-NutpF4 dev=hda2 ino=1144708
scontext=system_u:system_r:xdm_xserver_t
tcontext=system_u:object_r:var_run_t tclass=file

in my logs. Should the X server be allowed to do this?

Comment 1 Daniel Walsh 2004-03-18 05:09:56 UTC
Fixed in policy-1.9-1