Bug 344431
Summary: | SELinux denies /usr/bin/Xorg (xdm_xserver_t) "getattr" to /proc/5452/cmdline (unconfined_t) | ||
---|---|---|---|
Product: | [Fedora] Fedora | Reporter: | Julian Sikorski <belegdol> |
Component: | selinux-policy-targeted | Assignee: | Daniel Walsh <dwalsh> |
Status: | CLOSED CURRENTRELEASE | QA Contact: | Ben Levenson <benl> |
Severity: | low | Docs Contact: | |
Priority: | low | ||
Version: | rawhide | ||
Target Milestone: | --- | ||
Target Release: | --- | ||
Hardware: | All | ||
OS: | Linux | ||
Whiteboard: | |||
Fixed In Version: | 3.0.8-56.fc8 | Doc Type: | Bug Fix |
Doc Text: | Story Points: | --- | |
Clone Of: | Environment: | ||
Last Closed: | 2007-11-21 22:54:05 UTC | Type: | --- |
Regression: | --- | Mount Type: | --- |
Documentation: | --- | CRM: | |
Verified Versions: | Category: | --- | |
oVirt Team: | --- | RHEL 7.3 requirements from Atomic Host: | |
Cloudforms Team: | --- | Target Upstream Version: | |
Embargoed: |
Description
Julian Sikorski
2007-10-21 12:53:34 UTC
It would be nice to know what pid 5452 is; if you can reproduce this, what process is it trying to read the command line for? But I'm pretty sure this is something in the nvidia driver, nothing in plain X looks at /proc/*/cmdline that I know of. Allowed in 3.0.8-29.fc8 *** Bug 344421 has been marked as a duplicate of this bug. *** Huh? Are these two really the same? I mean, the audit messages are different: getattr to cmdline, and search to unknown. well yes, the firstone is trying to read the directory and the second one the file. So from my perspective we need to figure out wheter we want X to be able to read /proc/USER/* Thanks for clarification. Hmm, still present in 3.0.8-30.fc8. Maybe I need a relabel? Anyway, I'm going to try to figure out what the pid means, but this is kind of hard. This is because as short as 2 minutes after the SELinux denial pidof returns nothing. If the program is causing the denial on exit, we may never know. That is because I lied. Try 3.0.8-32.fc8 Hmm, denial still present. I'll run a relabel, just in case. Relabel did not help. Fixed in selinux-policy-3.0.8-56.fc8 |