Bug 657449

Summary: selinux alert
Product: [Fedora] Fedora Reporter: Jason M. Christos <jason.christos>
Component: 0xFFFFAssignee: Miroslav Grepl <mgrepl>
Status: CLOSED NOTABUG QA Contact: Fedora Extras Quality Assurance <extras-qa>
Severity: medium Docs Contact:
Priority: low    
Version: 13CC: dwalsh, dwmw2, jason.christos, mgrepl
Target Milestone: ---Keywords: Reopened
Target Release: ---   
Hardware: i686   
OS: Unspecified   
Whiteboard:
Fixed In Version: Doc Type: Bug Fix
Doc Text:
Story Points: ---
Clone Of: Environment:
Last Closed: 2010-12-01 15:51:41 UTC Type: ---
Regression: --- Mount Type: ---
Documentation: --- CRM:
Verified Versions: Category: ---
oVirt Team: --- RHEL 7.3 requirements from Atomic Host:
Cloudforms Team: --- Target Upstream Version:
Embargoed:
Attachments:
Description Flags
denials none

Description Jason M. Christos 2010-11-26 05:54:58 UTC
Description of problem: i dont understand selinux yet


Version-Release number of selected component (if applicable):


How reproducible: update selinux policy???


Steps to Reproduce:
1.
2.
3.
  
Actual results:


Expected results:

no selinux alerts

Additional info:

Comment 1 Miroslav Grepl 2010-11-28 23:03:05 UTC
Are you seeing any AVC messages in sealert? 

If so, please attach and reopen the bug.

Comment 2 Jason M. Christos 2010-11-29 13:38:49 UTC
Created attachment 463484 [details]
denials

semod denial on update to leak in temp file

Comment 3 Jason M. Christos 2010-11-29 13:39:37 UTC
i attached a txt file including avc denials to leaked file descriptor in semod

Comment 4 Miroslav Grepl 2010-12-01 15:51:41 UTC
Jason,
how is labeled /usr/libexec/packagekitd?

# ls -Z /usr/libexec/packagekitd


Should be

# ls -Z /usr/libexec/packagekitd 
-rwxr-xr-x. root root system_u:object_r:rpm_exec_t:s0  /usr/libexec/packagekitd


If your label is different (I mean "rpm_exec_t" label), execute

# restorecon -R -v /usr/libexec/packagekitd

Which will fix the bad label. If I am wrong and your label is correct, please reopen the bug.

Comment 5 Jason M. Christos 2010-12-02 10:08:28 UTC
you were right -rwxr-xr-x. root root system_u:object_r:bin_t:s0       /usr/libexec/packagekitd