Bug 244598

Summary: Prelink problem with nethack
Product: [Fedora] Fedora EPEL Reporter: Matthew Booth <mbooth>
Component: nethackAssignee: Luke Macken <lmacken>
Status: CLOSED WORKSFORME QA Contact: Fedora Extras Quality Assurance <extras-qa>
Severity: low Docs Contact:
Priority: low    
Version: el5CC: pfrields
Target Milestone: ---   
Target Release: ---   
Hardware: All   
OS: Linux   
Whiteboard:
Fixed In Version: Doc Type: Bug Fix
Doc Text:
Story Points: ---
Clone Of: Environment:
Last Closed: 2007-10-11 18:02:57 UTC Type: ---
Regression: --- Mount Type: ---
Documentation: --- CRM:
Verified Versions: Category: ---
oVirt Team: --- RHEL 7.3 requirements from Atomic Host:
Cloudforms Team: --- Target Upstream Version:
Embargoed:

Description Matthew Booth 2007-06-17 22:40:39 UTC
Description of problem:
After installing nethack, I get the following error nightly:

avc: denied { create } for comm="prelink" egid=0 euid=0 exe="/usr/sbin/prelink"
exit=-13 fsgid=0 fsuid=0 gid=0 items=0 name="nethack.#prelink#.cNGQAs" pid=20166
scontext=user_u:system_r:prelink_t:s0 sgid=0 subj=user_u:system_r:prelink_t:s0
suid=0 tclass=file tcontext=user_u:object_r:usr_t:s0 tty=(none) uid=0 

After a brief investigation of this problem, my best guess is that prelink is
trying to create a temporary file in /usr/games/nethack-3.4.3/. As this isn't a
regular location for binaries, it's not allowed to do this.

Although I haven't yet tinkered with the new modular SELinux stuff, my
understanding is that this is now an application packaging issue rather than a
central SELinux policy issue.

Version-Release number of selected component (if applicable):
nethack-3.4.3-12.el5.1.i386
selinux-policy-targeted-2.4.6-30.el5.noarch

How reproducible:
Always


Steps to Reproduce:
1. Install nethack
2. Leave SELinux in Enforcing mode
3. Wait for prelink to run
  
Actual results:
As above.

Expected results:
Prelink functions correctly.

Additional info:

Comment 1 Luke Macken 2007-10-11 18:02:57 UTC
13:58 =dwalsh> upgrade to the latest selinux policy.
13:58 =dwalsh> people.redhat.com/dwalsh/SELinux/RHEL5
13:59 =dwalsh> Should take care of it.