Bug 175487

Summary: new selinux policy prevent sol from running
Product: [Fedora] Fedora Reporter: Jason <dravet>
Component: guileAssignee: Phil Knirsch <pknirsch>
Status: CLOSED RAWHIDE QA Contact:
Severity: medium Docs Contact:
Priority: medium    
Version: 5CC: rstrode, rvokal
Target Milestone: ---   
Target Release: ---   
Hardware: i686   
OS: Linux   
Whiteboard:
Fixed In Version: Doc Type: Bug Fix
Doc Text:
Story Points: ---
Clone Of: Environment:
Last Closed: 2006-01-11 20:49:54 UTC Type: ---
Regression: --- Mount Type: ---
Documentation: --- CRM:
Verified Versions: Category: ---
oVirt Team: --- RHEL 7.3 requirements from Atomic Host:
Cloudforms Team: --- Target Upstream Version:
Embargoed:
Bug Depends On:    
Bug Blocks: 150222    

Description Jason 2005-12-11 19:59:43 UTC
From Bugzilla Helper:
User-Agent: Mozilla/5.0 (X11; U; Linux i686; en-US; rv:1.8) Gecko/20051129 Fedora/1.5-1 Firefox/1.5

Description of problem:
The new selinux policy prevents sol from running.  When I run sol I get the following error:
sol: error while loading shared libraries: libqthreads.so.12: cannot enable executable stack as shared object requires: Permission denied

I get the following in /var/log/audit/audit.log
type=AVC msg=audit(1134331204.241:168): avc:  denied  { execmem } for  pid=5005 comm="sol" scontext=root:system_r:unconfined_t:s0-s0:c0.c255 tcontext=root:system_r:unconfined_t:s0-s0:c0.c255 tclass=process
type=SYSCALL msg=audit(1134331204.241:168): arch=40000003 syscall=125 success=no exit=-13 a0=bf8fa000 a1=1000 a2=1000007 a3=b7fea7c8 items=0 pid=5005 auid=0 uid=0 gid=0 euid=0 suid=0 fsuid=0 egid=0 sgid=0 fsgid=0 comm="sol" exe="/usr/bin/sol"

See for details:
http://people.redhat.com/drepper/selinux-mem.html

I am running selinux-policy-targeted-2.1.2-1 in enforcing mode.

Version-Release number of selected component (if applicable):
gnome-games-2.13.2-1

How reproducible:
Always

Steps to Reproduce:
1.  install new selinux policy
2.  run sol
3.
  

Actual Results:  sol does not run

Expected Results:  sol and freecell should run

Additional info:

Comment 1 Jason 2005-12-11 20:01:48 UTC
I should note this is not a selinux problem.  The problem is within sol.  See
the following for details:
http://people.redhat.com/drepper/selinux-mem.html


Comment 2 Jason 2005-12-12 14:57:17 UTC
*** Bug 175488 has been marked as a duplicate of this bug. ***

Comment 3 Jason 2005-12-22 14:18:14 UTC
The gnome developers told me the problem is with quile.  I am reassigning the
issue to them.

Comment 4 Jason 2006-01-11 20:49:54 UTC
This problem was related to
https://bugzilla.redhat.com/bugzilla/show_bug.cgi?id=177121 and has since been
fixed.