Bug 459415
Summary: | prelude domain modifications | ||
---|---|---|---|
Product: | [Fedora] Fedora | Reporter: | Dominick Grift <domg444> |
Component: | selinux-policy | Assignee: | Daniel Walsh <dwalsh> |
Status: | CLOSED CURRENTRELEASE | QA Contact: | Fedora Extras Quality Assurance <extras-qa> |
Severity: | medium | Docs Contact: | |
Priority: | medium | ||
Version: | rawhide | CC: | rvokal |
Target Milestone: | --- | ||
Target Release: | --- | ||
Hardware: | All | ||
OS: | Linux | ||
Whiteboard: | |||
Fixed In Version: | Doc Type: | Bug Fix | |
Doc Text: | Story Points: | --- | |
Clone Of: | Environment: | ||
Last Closed: | 2008-11-17 22:05:34 UTC | Type: | --- |
Regression: | --- | Mount Type: | --- |
Documentation: | --- | CRM: | |
Verified Versions: | Category: | --- | |
oVirt Team: | --- | RHEL 7.3 requirements from Atomic Host: | |
Cloudforms Team: | --- | Target Upstream Version: | |
Embargoed: |
Description
Dominick Grift
2008-08-18 17:44:56 UTC
The optional policy block is wrong for corenetport... and file_search... By the way: snort module is still not installed. Can we have policy for snort? Fixes are in selinux-policy-3.5.5-1.fc10.src.rpm , including snort. Which will be available as soon as Fedora Infrastructure is back up and running. BTW, what is prelude searching for in /tmp? good question, i am not sure. ill keep an eye on that and lets you know if i figure it out. Well i went to #prelude and asked about it. Seems it has to do with the fact that the maintainer want prelude-manager to be able to run without user intervention. It appears that there is a scenario where prelude-manager creates a socket in /tmp. Maybe if prelude manager is started by a user instead of root. Not really sure but i seems the maintainer prefers /tmp over /var/run for this. Well the maintainer is wrong. System processes should not be creating things in /tmp. This is just asking for problems. If a user can control a directory where a nother process is trying to create things, it is a recipe for mischief, to put it mildly. Closing all bugs that have been in modified for over a month. Please reopen if the bug is not actually fixed. |