| Summary: | Firefox print to file triggers sealert | ||
|---|---|---|---|
| Product: | [Fedora] Fedora | Reporter: | Germano Massullo <germano.massullo> |
| Component: | selinux-policy-targeted | Assignee: | Lukas Vrabec <lvrabec> |
| Status: | CLOSED DUPLICATE | QA Contact: | Ben Levenson <benl> |
| Severity: | unspecified | Docs Contact: | |
| Priority: | unspecified | ||
| Version: | 24 | CC: | danysan95, dwalsh, juliux.pigface, robert.mader |
| Target Milestone: | --- | ||
| Target Release: | --- | ||
| Hardware: | Unspecified | ||
| OS: | Unspecified | ||
| Whiteboard: | |||
| Fixed In Version: | Doc Type: | If docs needed, set a value | |
| Doc Text: | Story Points: | --- | |
| Clone Of: | Environment: | ||
| Last Closed: | 2017-04-24 19:50:58 UTC | Type: | Bug |
| Regression: | --- | Mount Type: | --- |
| Documentation: | --- | CRM: | |
| Verified Versions: | Category: | --- | |
| oVirt Team: | --- | RHEL 7.3 requirements from Atomic Host: | |
| Cloudforms Team: | --- | Target Upstream Version: | |
I can confirm this on f25:
SELinux is preventing 57656220436F6E74656E74 from create access on the file mozilla.pdf.
***** Plugin mozplugger (99.1 confidence) suggests ************************
If you want to use the plugin package
Then you must turn off SELinux controls on the Firefox plugins.
Do
# setsebool -P unconfined_mozilla_plugin_transition 0
***** Plugin catchall (1.81 confidence) suggests **************************
If you believe that 57656220436F6E74656E74 should be allowed create access on the mozilla.pdf file by default.
Then you should report this as a bug.
You can generate a local policy module to allow this access.
Do
allow this access for now by executing:
# ausearch -c '57656220436F6E74656E74' --raw | audit2allow -M my-57656220436F6E74656E74
# semodule -X 300 -i my-57656220436F6E74656E74.pp
Additional Information:
Source Context unconfined_u:unconfined_r:mozilla_plugin_t:s0-s0:c
0.c1023
Target Context unconfined_u:object_r:user_home_dir_t:s0
Target Objects mozilla.pdf [ file ]
Source 57656220436F6E74656E74
Source Path 57656220436F6E74656E74
Port <Unknown>
Host robert.thinkpad-x230
Source RPM Packages
Target RPM Packages
Policy RPM selinux-policy-3.13.1-225.11.fc25.noarch
Selinux Enabled True
Policy Type targeted
Enforcing Mode Enforcing
Host Name robert.thinkpad-x230
Platform Linux robert.thinkpad-x230 4.9.13-201.fc25.x86_64
#1 SMP Tue Mar 7 23:47:11 UTC 2017 x86_64 x86_64
Alert Count 1
First Seen 2017-03-17 10:56:28 CET
Last Seen 2017-03-17 10:56:28 CET
Local ID 9f9ed087-955a-453a-91c8-4bbc44a707d8
Raw Audit Messages
type=AVC msg=audit(1489744588.5:344): avc: denied { create } for pid=3674 comm=57656220436F6E74656E74 name="mozilla.pdf" scontext=unconfined_u:unconfined_r:mozilla_plugin_t:s0-s0:c0.c1023 tcontext=unconfined_u:object_r:user_home_dir_t:s0 tclass=file permissive=0
Hash: 57656220436F6E74656E74,mozilla_plugin_t,user_home_dir_t,file,create
*** This bug has been marked as a duplicate of bug 1388312 *** |
In Firefox, I was trying to "Print to file" when I got this SELinux is preventing 57656220436F6E74656E74 from create access on the file file. ***** Plugin mozplugger (99.1 confidence) suggests ************************ If si vuole usare il pacchetto plugin Then disabilitare i controlli SELinux sui plugin di Firefox. Do # setsebool -P unconfined_mozilla_plugin_transition 0 ***** Plugin catchall (1.81 confidence) suggests ************************** If si crede che 57656220436F6E74656E74 dovrebbe avere possibilità di accesso create sui file file in modo predefinito. Then si dovrebbe riportare il problema come bug. E' possibile generare un modulo di politica locale per consentire questo accesso. Do allow this access for now by executing: # ausearch -c '57656220436F6E74656E74' --raw | audit2allow -M my-57656220436F6E74656E74 # semodule -X 300 -i my-57656220436F6E74656E74.pp Additional Information: Source Context unconfined_u:unconfined_r:mozilla_plugin_t:s0-s0:c 0.c1023 Target Context unconfined_u:object_r:user_home_t:s0 Target Objects file [ file ] Source 57656220436F6E74656E74 Source Path 57656220436F6E74656E74 Port <Unknown> Source RPM Packages Target RPM Packages Policy RPM selinux-policy-3.13.1-191.19.fc24.noarch Selinux Enabled True Policy Type targeted Enforcing Mode Enforcing Platform Linux host 4.8.4-200.fc24.x86_64 #1 SMP Tue Oct 25 13:06:04 UTC 2016 x86_64 x86_64 Alert Count 1 First Seen 2016-11-08 11:45:59 CET Last Seen 2016-11-08 11:45:59 CET Raw Audit Messages type=AVC msg=audit(1478601959.936:350): avc: denied { create } for pid=2248 comm=57656220436F6E74656E74 name="file" scontext=unconfined_u:unconfined_r:mozilla_plugin_t:s0-s0:c0.c1023 tcontext=unconfined_u:object_r:user_home_t:s0 tclass=file permissive=0 Hash: 57656220436F6E74656E74,mozilla_plugin_t,user_home_t,file,create