Bug 542312
Summary: | SELinux is preventing /sbin/setfiles access to a leaked /home/amessina/.xsession-errors-:0 file descriptor. | ||
---|---|---|---|
Product: | [Fedora] Fedora | Reporter: | Anthony Messina <amessina> |
Component: | kdebase-workspace | Assignee: | Than Ngo <than> |
Status: | CLOSED ERRATA | QA Contact: | Fedora Extras Quality Assurance <extras-qa> |
Severity: | medium | Docs Contact: | |
Priority: | low | ||
Version: | 12 | CC: | dwalsh, fedora, fedora, jreznik, kevin, lorenzo, ltinkl, mgrepl, rdieter, rstrode, smparrish, than |
Target Milestone: | --- | Keywords: | Reopened |
Target Release: | --- | ||
Hardware: | x86_64 | ||
OS: | Linux | ||
Whiteboard: | setroubleshoot_trace_hash:37fc4f78215f7fe432b247ad1fd2826e40767420e1638d6bf6d33edf97f6a7fe | ||
Fixed In Version: | 4.3.80-4 | Doc Type: | Bug Fix |
Doc Text: | Story Points: | --- | |
Clone Of: | Environment: | ||
Last Closed: | 2010-02-24 06:05:01 UTC | Type: | --- |
Regression: | --- | Mount Type: | --- |
Documentation: | --- | CRM: | |
Verified Versions: | Category: | --- | |
oVirt Team: | --- | RHEL 7.3 requirements from Atomic Host: | |
Cloudforms Team: | --- | Target Upstream Version: | |
Embargoed: | |||
Bug Depends On: | 533921 | ||
Bug Blocks: |
Description
Anthony Messina
2009-11-29 09:14:22 UTC
You can add these rules for now using # grep avc /var/log/audit/audit.log | audit2allow -M mypol # semodule -i mypol.pp Fixed in selinux-policy-3.6.32-52.fc12.noarch Are you using kdm for login? I do use KDM and I also have my /home dirs mounted over NFS with krb5p. This is a bug in SELInux-policy but I wanted to change this bug to kdebase, because the kdm should be opening the xsession-errors file for append instead of write. This is what gdm is doing. If you do this, I can change the access to allow and prevent a confined application from clearing all data in the .xsession-errors file. KDM is actually in kdebase-workspace. An ever-growing ~/.xsession-errors is preferable ? really? It is fine if xdm truncates the file, which is also what gdm does, but pass the descriptor as append only for the session. * Fri Dec 11 2009 Rex Dieter <rdieter> 4.3.80-4 - SELinux is preventing access to a leaked .xsession-errors-:0 file descriptor (#542312) akonadi-1.3.1-2.fc11,arora-0.10.2-3.fc11,compiz-0.7.8-20.fc11,digikam-1.1.0-2.fc11,kbluetooth-0.4.1-2.fc11,kcoloredit-4.4.0-2.fc11,kdeaccessibility-4.4.0-1.fc11,kdeadmin-4.4.0-2.fc11,kdeartwork-4.4.0-1.fc11,kdebase-4.4.0-3.fc11,kdebase-runtime-4.4.0-3.fc11,kdebase-workspace-4.4.0-7.fc11,kdebindings-4.4.0-1.fc11,kdeedu-4.4.0-1.fc11,kdegames-4.4.0-2.fc11,kdegraphics-4.4.0-1.fc11,kde-l10n-4.4.0-1.fc11,kdelibs-4.4.0-9.fc11,kdemultimedia-4.4.0-1.fc11,kdenetwork-4.4.0-2.fc11,kdepim-4.4.0-5.fc11,kdepimlibs-4.4.0-2.fc11,kdepim-runtime-4.4.0-4.fc11,kdeplasma-addons-4.4.0-1.fc11,kde-plasma-networkmanagement-0.9-0.12.20100220.fc11,kde-plasma-smooth-tasks-0.0.1-0.1.wip20091206.fc11.1,kde-plasma-stasks-0.5.1-7.fc11,kde-plasma-yawp-0.3.2-2.fc11,kdesdk-4.4.0-1.fc11,kde-settings-4.2-17,kdetoys-4.4.0-1.fc11,kdeutils-4.4.0-1.fc11,kgrab-0.1.1-22.fc11,kiconedit-4.4.0-1.fc11,kio_gopher-0.1.3-3.fc11,kipi-plugins-1.1.0-1.fc11.2,konq-plugins-4.4.0-2.fc11,kopete-cryptography-1.3.0-16.fc11,kphotoalbum-4.1.1-5.fc11,kpilot-5.3.0-4.fc11,oxygen-icon-theme-4.4.0-2.fc11,polkit-qt-0.9.3-2.fc11,PyKDE-3.16.6-3.fc11,PyQt-3.18.1-6.fc11,PyQt4-4.7-1.fc11,qedje-0.4.0-6.fc11,qgis-1.0.2-6.fc11,qscintilla-2.4.2-1.fc11,qt-4.6.2-1.fc11,qt-creator-1.3.1-2.fc11,qtscriptgenerator-0.1.0-10.fc11,qzion-0.4.0-7.fc11,scidavis-0.2.3-13.fc11,sip-4.10-1.fc11,skanlite-0.4-1.fc11,soprano-2.4.0.1-1.fc11,strigi-0.7.2-2.fc11,virtuoso-opensource-6.1.0-2.fc11,webkitkde-0.0.5-0.1.svn1088283.fc11,PyQwt-5.2.0-4.fc11,qbittorrent-1.4.1-3.fc11,frescobaldi-1.0.2-1.fc11 has been submitted as an update for Fedora 11. http://admin.fedoraproject.org/updates/F11/FEDORA-2010-1850 akonadi-1.3.1-2.fc12,arora-0.10.2-3.fc12,avogadro-1.0.0-3.fc12,compiz-0.8.2-24.fc12,digikam-1.1.0-2.fc12,kbluetooth-0.4.1-2.fc12,kcoloredit-4.4.0-2.fc12,kdeaccessibility-4.4.0-1.fc12,kdeadmin-4.4.0-2.fc12,kdeartwork-4.4.0-1.fc12,kdebase-4.4.0-3.fc12,kdebase-runtime-4.4.0-3.fc12,kdebase-workspace-4.4.0-7.fc12,kdebindings-4.4.0-1.fc12,kdeedu-4.4.0-1.fc12,kdegames-4.4.0-2.fc12,kdegraphics-4.4.0-1.fc12,kdelibs-4.4.0-9.fc12,kdemultimedia-4.4.0-1.fc12,kdenetwork-4.4.0-2.fc12,kdepim-4.4.0-5.fc12,kdepimlibs-4.4.0-2.fc12,kdepim-runtime-4.4.0-4.fc12,kdeplasma-addons-4.4.0-1.fc12,kde-l10n-4.4.0-1.fc12,kde-plasma-networkmanagement-0.9-0.12.20100220.fc12,kde-plasma-smooth-tasks-0.0.1-0.1.wip20091206.fc12.1,kde-plasma-stasks-0.5.1-7.fc12,kde-plasma-yawp-0.3.2-2.fc12,kdesdk-4.4.0-1.fc12,kde-settings-4.3-17,kdetoys-4.4.0-1.fc12,kdeutils-4.4.0-1.fc12,kgrab-0.1.1-22.fc12,kiconedit-4.4.0-1.fc12,kio_gopher-0.1.3-3.fc12,kipi-plugins-1.1.0-1.fc12.2,konq-plugins-4.4.0-2.fc12,kopete-cryptography-1.3.0-16.fc12,kphotoalbum-4.1.1-5.fc12,kpilot-5.3.0-4.fc12,oxygen-icon-theme-4.4.0-2.fc12,polkit-qt-0.95.1-3.fc12,PyKDE-3.16.6-3.fc12,PyQt-3.18.1-6.fc12,PyQt4-4.7-1.fc12,qedje-0.4.0-6.fc12,qgis-1.0.2-6.fc12,qscintilla-2.4.2-1.fc12,qt-4.6.2-1.fc12,qt-creator-1.3.1-2.fc12,qtscriptgenerator-0.1.0-10.fc12,qzion-0.4.0-7.fc12,scidavis-0.2.3-13.fc12,sip-4.10-1.fc12,skanlite-0.4-1.fc12,soprano-2.4.0.1-1.fc12,strigi-0.7.2-2.fc12,virtuoso-opensource-6.1.0-2.fc12,webkitkde-0.0.5-0.1.svn1088283.fc12,PyQwt-5.2.0-4.fc12,qbittorrent-2.1.5-4.fc12,frescobaldi-1.0.2-1.fc12 has been submitted as an update for Fedora 12. http://admin.fedoraproject.org/updates/akonadi-1.3.1-2.fc12,arora-0.10.2-3.fc12,avogadro-1.0.0-3.fc12,compiz-0.8.2-24.fc12,digikam-1.1.0-2.fc12,kbluetooth-0.4.1-2.fc12,kcoloredit-4.4.0-2.fc12,kdeaccessibility-4.4.0-1.fc12,kdeadmin-4.4.0-2.fc12,kdeartwork-4.4.0-1.fc12,kdebase-4.4.0-3.fc12,kdebase-runtime-4.4.0-3.fc12,kdebase-workspace-4.4.0-7.fc12,kdebindings-4.4.0-1.fc12,kdeedu-4.4.0-1.fc12,kdegames-4.4.0-2.fc12,kdegraphics-4.4.0-1.fc12,kdelibs-4.4.0-9.fc12,kdemultimedia-4.4.0-1.fc12,kdenetwork-4.4.0-2.fc12,kdepim-4.4.0-5.fc12,kdepimlibs-4.4.0-2.fc12,kdepim-runtime-4.4.0-4.fc12,kdeplasma-addons-4.4.0-1.fc12,kde-l10n-4.4.0-1.fc12,kde-plasma-networkmanagement-0.9-0.12.20100220.fc12,kde-plasma-smooth-tasks-0.0.1-0.1.wip20091206.fc12.1,kde-plasma-stasks-0.5.1-7.fc12,kde-plasma-yawp-0.3.2-2.fc12,kdesdk-4.4.0-1.fc12,kde-settings-4.3-17,kdetoys-4.4.0-1.fc12,kdeutils-4.4.0-1.fc12,kgrab-0.1.1-22.fc12,kiconedit-4.4.0-1.fc12,kio_gopher-0.1.3-3.fc12,kipi-plugins-1.1.0-1.fc12.2,konq-plugins-4.4.0-2.fc12,kopete-cryptography-1.3.0-16.fc12,kphotoalbum-4.1.1-5.fc12,kpilot-5.3.0-4.fc12,oxygen-icon-theme-4.4.0-2.fc12,polkit-qt-0.95.1-3.fc12,PyKDE-3.16.6-3.fc12,PyQt-3.18.1-6.fc12,PyQt4-4.7-1.fc12,qedje-0.4.0-6.fc12,qgis-1.0.2-6.fc12,qscintilla-2.4.2-1.fc12,qt-4.6.2-1.fc12,qt-creator-1.3.1-2.fc12,qtscriptgenerator-0.1.0-10.fc12,qzion-0.4.0-7.fc12,scidavis-0.2.3-13.fc12,sip-4.10-1.fc12,skanlite-0.4-1.fc12,soprano-2.4.0.1-1.fc12,strigi-0.7.2-2.fc12,virtuoso-opensource-6.1.0-2.fc12,webkitkde-0.0.5-0.1.svn1088283.fc12,PyQwt-5.2.0-4.fc12,qbittorrent-2.1.5-4.fc12,frescobaldi-1.0.2-1.fc12 kbluetooth-0.4.1-2.fc12, kdebase-workspace-4.4.0-7.fc12, kdelibs-4.4.0-9.fc12, kdepim-4.4.0-5.fc12, kde-plasma-networkmanagement-0.9-0.12.20100220.fc12, qt-4.6.2-1.fc12, qbittorrent-2.1.5-4.fc12, frescobaldi-1.0.2-1.fc12, akonadi-1.3.1-2.fc12, arora-0.10.2-3.fc12, avogadro-1.0.0-3.fc12, compiz-0.8.2-24.fc12, digikam-1.1.0-2.fc12, kcoloredit-4.4.0-2.fc12, kdeaccessibility-4.4.0-1.fc12, kdeadmin-4.4.0-2.fc12, kdeartwork-4.4.0-1.fc12, kdebase-4.4.0-3.fc12, kdebase-runtime-4.4.0-3.fc12, kdebindings-4.4.0-1.fc12, kdeedu-4.4.0-1.fc12, kdegames-4.4.0-2.fc12, kdegraphics-4.4.0-1.fc12, kdemultimedia-4.4.0-1.fc12, kdenetwork-4.4.0-2.fc12, kdepimlibs-4.4.0-2.fc12, kdeplasma-addons-4.4.0-1.fc12, kde-l10n-4.4.0-1.fc12, kde-plasma-smooth-tasks-0.0.1-0.1.wip20091206.fc12.1, kde-plasma-stasks-0.5.1-7.fc12, kde-plasma-yawp-0.3.2-2.fc12, kdesdk-4.4.0-1.fc12, kde-settings-4.3-17, kdetoys-4.4.0-1.fc12, kdeutils-4.4.0-1.fc12, kgrab-0.1.1-22.fc12, kiconedit-4.4.0-1.fc12, kio_gopher-0.1.3-3.fc12, kipi-plugins-1.1.0-1.fc12.2, konq-plugins-4.4.0-2.fc12, kopete-cryptography-1.3.0-16.fc12, kphotoalbum-4.1.1-5.fc12, kpilot-5.3.0-4.fc12, oxygen-icon-theme-4.4.0-2.fc12, polkit-qt-0.95.1-3.fc12, PyKDE-3.16.6-3.fc12, PyQt-3.18.1-6.fc12, PyQt4-4.7-1.fc12, qedje-0.4.0-6.fc12, qgis-1.0.2-6.fc12, qscintilla-2.4.2-1.fc12, qt-creator-1.3.1-2.fc12, qtscriptgenerator-0.1.0-10.fc12, qzion-0.4.0-7.fc12, scidavis-0.2.3-13.fc12, sip-4.10-1.fc12, skanlite-0.4-1.fc12, soprano-2.4.0.1-1.fc12, strigi-0.7.2-2.fc12, virtuoso-opensource-6.1.0-2.fc12, webkitkde-0.0.5-0.1.svn1088283.fc12, kdepim-runtime-4.4.0-4.fc12, PyQwt-5.2.0-4.fc12 has been pushed to the Fedora 12 testing repository. If problems still persist, please make note of it in this bug report. If you want to test the update, you can install it with su -c 'yum --enablerepo=updates-testing update kbluetooth kdebase-workspace kdelibs kdepim kde-plasma-networkmanagement qt qbittorrent frescobaldi akonadi arora avogadro compiz digikam kcoloredit kdeaccessibility kdeadmin kdeartwork kdebase kdebase-runtime kdebindings kdeedu kdegames kdegraphics kdemultimedia kdenetwork kdepimlibs kdeplasma-addons kde-l10n kde-plasma-smooth-tasks kde-plasma-stasks kde-plasma-yawp kdesdk kde-settings kdetoys kdeutils kgrab kiconedit kio_gopher kipi-plugins konq-plugins kopete-cryptography kphotoalbum kpilot oxygen-icon-theme polkit-qt PyKDE PyQt PyQt4 qedje qgis qscintilla qt-creator qtscriptgenerator qzion scidavis sip skanlite soprano strigi virtuoso-opensource webkitkde kdepim-runtime PyQwt'. You can provide feedback for this update here: http://admin.fedoraproject.org/updates/F12/FEDORA-2010-2579 kbluetooth-0.4.1-2.fc12, kdebase-workspace-4.4.0-7.fc12, kdelibs-4.4.0-9.fc12, kdepim-4.4.0-5.fc12, kde-plasma-networkmanagement-0.9-0.12.20100220.fc12, qt-4.6.2-1.fc12, qbittorrent-2.1.5-4.fc12, frescobaldi-1.0.2-1.fc12, akonadi-1.3.1-2.fc12, arora-0.10.2-3.fc12, avogadro-1.0.0-3.fc12, compiz-0.8.2-24.fc12, digikam-1.1.0-2.fc12, kcoloredit-4.4.0-2.fc12, kdeaccessibility-4.4.0-1.fc12, kdeadmin-4.4.0-2.fc12, kdeartwork-4.4.0-1.fc12, kdebase-4.4.0-3.fc12, kdebase-runtime-4.4.0-3.fc12, kdebindings-4.4.0-1.fc12, kdeedu-4.4.0-1.fc12, kdegames-4.4.0-2.fc12, kdegraphics-4.4.0-1.fc12, kdemultimedia-4.4.0-1.fc12, kdenetwork-4.4.0-2.fc12, kdepimlibs-4.4.0-2.fc12, kdeplasma-addons-4.4.0-1.fc12, kde-l10n-4.4.0-1.fc12, kde-plasma-smooth-tasks-0.0.1-0.1.wip20091206.fc12.1, kde-plasma-stasks-0.5.1-7.fc12, kde-plasma-yawp-0.3.2-2.fc12, kdesdk-4.4.0-1.fc12, kde-settings-4.3-17, kdetoys-4.4.0-1.fc12, kdeutils-4.4.0-1.fc12, kgrab-0.1.1-22.fc12, kiconedit-4.4.0-1.fc12, kio_gopher-0.1.3-3.fc12, kipi-plugins-1.1.0-1.fc12.2, konq-plugins-4.4.0-2.fc12, kopete-cryptography-1.3.0-16.fc12, kphotoalbum-4.1.1-5.fc12, kpilot-5.3.0-4.fc12, oxygen-icon-theme-4.4.0-2.fc12, polkit-qt-0.95.1-3.fc12, PyKDE-3.16.6-3.fc12, PyQt-3.18.1-6.fc12, PyQt4-4.7-1.fc12, qedje-0.4.0-6.fc12, qgis-1.0.2-6.fc12, qscintilla-2.4.2-1.fc12, qt-creator-1.3.1-2.fc12, qtscriptgenerator-0.1.0-10.fc12, qzion-0.4.0-7.fc12, scidavis-0.2.3-13.fc12, sip-4.10-1.fc12, skanlite-0.4-1.fc12, soprano-2.4.0.1-1.fc12, strigi-0.7.2-2.fc12, virtuoso-opensource-6.1.0-2.fc12, webkitkde-0.0.5-0.1.svn1088283.fc12, kdepim-runtime-4.4.0-4.fc12, PyQwt-5.2.0-4.fc12 has been pushed to the Fedora 12 stable repository. If problems still persist, please make note of it in this bug report. kbluetooth-0.4.1-2.fc11, kdebase-workspace-4.4.0-7.fc11, kdelibs-4.4.0-9.fc11, kdepim-4.4.0-5.fc11, kde-plasma-networkmanagement-0.9-0.12.20100220.fc11, qt-4.6.2-1.fc11, qbittorrent-1.4.1-3.fc11, frescobaldi-1.0.2-1.fc11, akonadi-1.3.1-2.fc11, arora-0.10.2-3.fc11, compiz-0.7.8-20.fc11, digikam-1.1.0-2.fc11, kcoloredit-4.4.0-2.fc11, kdeaccessibility-4.4.0-1.fc11, kdeadmin-4.4.0-2.fc11, kdeartwork-4.4.0-1.fc11, kdebase-4.4.0-3.fc11, kdebase-runtime-4.4.0-3.fc11, kdebindings-4.4.0-1.fc11, kdeedu-4.4.0-1.fc11, kdegames-4.4.0-2.fc11, kdegraphics-4.4.0-1.fc11, kde-l10n-4.4.0-1.fc11, kdemultimedia-4.4.0-1.fc11, kdenetwork-4.4.0-2.fc11, kdepimlibs-4.4.0-2.fc11, kdeplasma-addons-4.4.0-1.fc11, kde-plasma-smooth-tasks-0.0.1-0.1.wip20091206.fc11.1, kde-plasma-stasks-0.5.1-7.fc11, kde-plasma-yawp-0.3.2-2.fc11, kdesdk-4.4.0-1.fc11, kde-settings-4.2-17, kdetoys-4.4.0-1.fc11, kdeutils-4.4.0-1.fc11, kgrab-0.1.1-22.fc11, kiconedit-4.4.0-1.fc11, kio_gopher-0.1.3-3.fc11, kipi-plugins-1.1.0-1.fc11.2, konq-plugins-4.4.0-2.fc11, kopete-cryptography-1.3.0-16.fc11, kphotoalbum-4.1.1-5.fc11, kpilot-5.3.0-4.fc11, oxygen-icon-theme-4.4.0-2.fc11, polkit-qt-0.9.3-2.fc11, PyKDE-3.16.6-3.fc11, PyQt-3.18.1-6.fc11, PyQt4-4.7-1.fc11, qedje-0.4.0-6.fc11, qgis-1.0.2-6.fc11, qscintilla-2.4.2-1.fc11, qt-creator-1.3.1-2.fc11, qtscriptgenerator-0.1.0-10.fc11, qzion-0.4.0-7.fc11, scidavis-0.2.3-13.fc11, sip-4.10-1.fc11, skanlite-0.4-1.fc11, soprano-2.4.0.1-1.fc11, strigi-0.7.2-2.fc11, virtuoso-opensource-6.1.0-2.fc11, webkitkde-0.0.5-0.1.svn1088283.fc11, kdepim-runtime-4.4.0-4.fc11, PyQwt-5.2.0-4.fc11 has been pushed to the Fedora 11 stable repository. If problems still persist, please make note of it in this bug report. |