Bug 374011
Summary: | SELinux is preventing /usr/bin/kdm (xdm_t) "execute" to (bootloader_exec_t). | ||||||
---|---|---|---|---|---|---|---|
Product: | [Fedora] Fedora | Reporter: | Konstantin Svist <fry.kun> | ||||
Component: | kdebase | Assignee: | Than Ngo <than> | ||||
Status: | CLOSED WONTFIX | QA Contact: | Fedora Extras Quality Assurance <extras-qa> | ||||
Severity: | medium | Docs Contact: | |||||
Priority: | low | ||||||
Version: | 8 | CC: | kevin, ltinkl, rdieter, than | ||||
Target Milestone: | --- | ||||||
Target Release: | --- | ||||||
Hardware: | i686 | ||||||
OS: | Linux | ||||||
Whiteboard: | |||||||
Fixed In Version: | Doc Type: | Bug Fix | |||||
Doc Text: | Story Points: | --- | |||||
Clone Of: | Environment: | ||||||
Last Closed: | 2008-05-07 18:19:22 UTC | Type: | --- | ||||
Regression: | --- | Mount Type: | --- | ||||
Documentation: | --- | CRM: | |||||
Verified Versions: | Category: | --- | |||||
oVirt Team: | --- | RHEL 7.3 requirements from Atomic Host: | |||||
Cloudforms Team: | --- | Target Upstream Version: | |||||
Embargoed: | |||||||
Attachments: |
|
Description
Konstantin Svist
2007-11-09 23:03:26 UTC
Forgot to mention in case you don't know how to enable KDM as the login manager: edit file /etc/sysconfig/desktop (create if doesn't already exist) and add a following line to it: DISPLAYMANAGER="KDE" This will make kdm the default login manager and KDE the default environment. Update: the error also appears without actually logging out; it's sufficient to select Log Out from the KDE menu, and cancel out of it. I cannot reproduce locally. Have you modified kdm's setup in anyway (to vary from the stock defaults)? Further, please 1. ensure your box is fully up-to-date 2. try touch /.autorelabel and reboot Does the problem persist? Yes, the problem remains after relabel. The necessary parts to get this bug: 1) set the default window manager AND login manager to KDE/kdm - I used the method described in Comment #1 2) select "Grub" as the boot manager as described in "Steps to reproduce" in the original bug description. I verified that when I set boot manager to default "None", then log out and log back in - the problem disappears. It appears that logging out at least once is necessary for the setting to take full effect (and thus the bug to start/stop showing up) What's the purpose of your setting the boot manager option to "grub" (afaik, that's the default anyway)? This is not for "enabling grub" - this is for a nice KDE extra feature: if you have multiple grub entries, you may choose one to reboot to, in the logout dialog - during such reboot, the system doesn't make grub wait for input and just boots to whatever target you have chosen. For example, if you have a dual-boot with WinXP and Fedora is default, you can choose "reboot to Windows" neat, so neat in fact I think we need to make that the default behavior, imo. So, other than seeing the selinux alert, do you experience any concrete problems? Hrm, I can't get get this feature to work. With or without selinux being enabled. (In reply to comment #8) > Hrm, I can't get get this feature to work. With or without selinux being enabled. /etc/sysconfig/desktop should have DISPLAYMANAGER="KDE" DESKTOP="KDE" and you should be running a KDE session :) Yes, I have all that, it's the "if you have multiple grub entries, you may choose one to reboot to, in the logout dialog" feature that doesn't work for me. Created attachment 295313 [details] boot choice example (In reply to comment #10) > Yes, I have all that, it's the > "if you have multiple grub entries, you may choose one to reboot to, in the > logout dialog" > feature that doesn't work for me. I don't know what to tell you, then :( As far as I know, using KDM/KDE and setting grub as the bootloader enables this menu (see screenshot) P.S. have to press down and hold the reboot button for the menu to appear - otherwise it just follows default reboot Thanks! It was the "Press down and hold" part that I was missing. Real Neat. Reassigning selinux-policy-targetted, see if we can get it updated to allow this. Daniel, what do you think of allowing kdm the ability to nudge grub to select the next boot selection? This looks like when you login you are running as xdm_t which is the problem. You should be logged in as unconfined_t. I think you have a problem with your pam configuration. Login, run a shell $ id -Z Should show unconfined_t, if it shows xdm_t you never transitioned properly. For me (on my f7 box) anyway: $ id -Z user_u:system_r:unconfined_t Alright I read the bug again. The login program will allow a non logged in user to change the way the machine reboots? (In reply to comment #17) > Alright I read the bug again. The login program will allow a non logged in user > to change the way the machine reboots? Yes, the dialog for rebooting while not logged in also changes. (You probably already know this, but that dialog looks a little different) I can't confirm if that one also causes selinux error, since I'm running with selinux disabled (got really tired of all the warnings I can't even understand most of the time) Re: Dan's comment #17: That's the gist of it, yeah. grub has a feature to be able to specify the default choice of the next boot, we'd like to allow kdm to use that. Feel free to respond with "what kind of crack are you smoking?" if you're not keen on allowing that via selinux-policy. Konstantin, I don't know what your problem was/is, but the Bootloader=Grub feature worksforme on f7,f8 using selinux-policy-targeted Please consider relabeling your filesystem, and see if the problem(s) persist: touch /.autorelabel (re)enable selinux (if disabled, not just in permissive mode) reboot I talked to the gdm developers and they think this is crackrock and should be removed from kdm. Allowing a non logged in user to change the boot/runlevel is not considered a great idea. Can you give a justification for this? Shrug, folks can already tell the system to shutdown/restart on the login screen, then wait, and choose the next boot choice when grub's menu appears. kdm is simply offering the ability to skip the wait. But, as I said in comment #20, it would appear, afaict, that this feature works *now*. That said, I'm definitely ok concluding that this is all crackrock security-wise (and not enabling this feature by default). What about an X Screen where I don't have access to the console? Does this work when I have a grub password? Of course some people argue that allowing the machine to be rebooted without logging in is also a security flaw. :^( We're talking about defaults here, where kdm 1. Doesn't allow remote XDMCP 2. even with remote/xdmcp, non-local connections aren't allowed shutdown/reboot options anyway Wrt, grub passwords, dunno. I thought that only affected a users ability to modify an existing grub entry, not restrict which entries are choosable. I have no idea, I am just throwing out possible problems with this. Dan, thanks, so, afaict, the only low-priority issue I see left is whether selinux policy should address the "/usr/bin/kdm (xdm_t) "execute" to <Unknown> (bootloader_exec_t)" logged message or not. If the answer is no, then feel free to re-assign this back to kdebase. I don't think fedora should support this feature. OK, you heard the man, WONTFIX. Feel free to enable the feature and create a custom local selinux policy to allow that at your site. |