Bug 697207

Summary: at gdm login ... SELinux is preventing /usr/bin/gok from read access on the directory
Product: [Fedora] Fedora Reporter: Wendell Baker <wendellcraigbaker>
Component: selinux-policyAssignee: Miroslav Grepl <mgrepl>
Status: CLOSED WONTFIX QA Contact: Fedora Extras Quality Assurance <extras-qa>
Severity: unspecified Docs Contact:
Priority: unspecified    
Version: 14CC: davidz, dominick.grift, dwalsh, mgrepl, pertusus, tsmetana
Target Milestone: ---   
Target Release: ---   
Hardware: Unspecified   
OS: Unspecified   
Whiteboard:
Fixed In Version: Doc Type: Bug Fix
Doc Text:
Story Points: ---
Clone Of:
: 760990 (view as bug list) Environment:
Last Closed: 2012-08-16 14:41:19 UTC Type: ---
Regression: --- Mount Type: ---
Documentation: --- CRM:
Verified Versions: Category: ---
oVirt Team: --- RHEL 7.3 requirements from Atomic Host:
Cloudforms Team: --- Target Upstream Version:
Bug Depends On:    
Bug Blocks: 760990    
Attachments:
Description Flags
sudo sealert -l 82c72044-db37-4c34-b62c-0fd3f2ca4205
none
sudo sealert -l 25cfa985-f3d7-4be3-b4ab-4bfc126b7e7b
none
sudo sealert -l 237e8dae-b133-4c66-9c96-54e78f8b1934
none
sudo sealert -l 384cb886-46a9-4cf7-92d2-d72d9e72ee32 none

Description Wendell Baker 2011-04-16 20:55:08 UTC
Created attachment 492629 [details]
sudo sealert  -l 82c72044-db37-4c34-b62c-0fd3f2ca4205

Description of problem:

gok seems to need access to some places that selinux doesn't expect

Version-Release number of selected component (if applicable):

$ rpm -q -f /usr/bin/gok
gok-2.30.1-1.fc14.i686


How reproducible:

very

Steps to Reproduce:
1. reboot
2. start up gok (accessibility, on screen keyboard)
3. see messages in /var/log/messages
  
Actual results:

messages ... shown

Expected results:

no messages

Additional info:



from /var/log/messages

Apr 16 13:33:36 pert setroubleshoot: SELinux is preventing /usr/bin/gok from rea
d access on the directory /var/games. For complete SELinux messages. run sealert -l 384cb886-46a9-4cf7-92d2-d72d9e72ee32
Apr 16 13:33:36 pert setroubleshoot: SELinux is preventing /usr/bin/gok from read access on the directory /var/yp. For complete SELinux messages. run sealert -l 237e8dae-b133-4c66-9c96-54e78f8b1934
Apr 16 13:33:37 pert setroubleshoot: SELinux is preventing /usr/bin/gok from read access on the directory /var/www. For complete SELinux messages. run sealert -l 25cfa985-f3d7-4be3-b4ab-4bfc126b7e7b
Apr 16 13:33:37 pert setroubleshoot: SELinux is preventing /usr/bin/gok from read access on the directory /var/racoon. For complete SELinux messages. run sealert -l 82c72044-db37-4c34-b62c-0fd3f2ca4205
Apr 16 13:33:48 pert setroubleshoot: SELinux is preventing /usr/bin/gok from read access on the directory /var/games. For complete SELinux messages. run sealert -l 384cb886-46a9-4cf7-92d2-d72d9e72ee32
Apr 16 13:33:49 pert setroubleshoot: SELinux is preventing /usr/bin/gok from read access on the directory /var/yp. For complete SELinux messages. run sealert -l 237e8dae-b133-4c66-9c96-54e78f8b1934
Apr 16 13:33:49 pert setroubleshoot: SELinux is preventing /usr/bin/gok from read access on the directory /var/www. For complete SELinux messages. run sealert -l 25cfa985-f3d7-4be3-b4ab-4bfc126b7e7b
Apr 16 13:33:50 pert setroubleshoot: SELinux is preventing /usr/bin/gok from read access on the directory /var/racoon. For complete SELinux messages. run sealert -l 82c72044-db37-4c34-b62c-0fd3f2ca4205

Comment 1 Wendell Baker 2011-04-16 20:57:00 UTC
Created attachment 492630 [details]
sudo sealert -l 25cfa985-f3d7-4be3-b4ab-4bfc126b7e7b

Comment 2 Wendell Baker 2011-04-16 20:57:33 UTC
Created attachment 492631 [details]
sudo sealert -l 237e8dae-b133-4c66-9c96-54e78f8b1934

Comment 3 Wendell Baker 2011-04-16 20:58:29 UTC
Created attachment 492632 [details]
sudo sealert -l 384cb886-46a9-4cf7-92d2-d72d9e72ee32

Comment 4 David Zeuthen 2011-12-07 15:47:00 UTC
Can't really do anything about SELinux policy, sorry. Reassigning.

Comment 5 Daniel Walsh 2011-12-07 16:52:16 UTC
David the question here is why is gok listing the contents of /var?  It really has nothing to do with SELinux, other then we have to dontaudit some questionable behaviour.

Comment 6 Fedora End Of Life 2012-08-16 14:41:23 UTC
This message is a notice that Fedora 14 is now at end of life. Fedora 
has stopped maintaining and issuing updates for Fedora 14. It is 
Fedora's policy to close all bug reports from releases that are no 
longer maintained.  At this time, all open bugs with a Fedora 'version'
of '14' have been closed as WONTFIX.

(Please note: Our normal process is to give advanced warning of this 
occurring, but we forgot to do that. A thousand apologies.)

Package Maintainer: If you wish for this bug to remain open because you
plan to fix it in a currently maintained version, feel free to reopen 
this bug and simply change the 'version' to a later Fedora version.

Bug Reporter: Thank you for reporting this issue and we are sorry that 
we were unable to fix it before Fedora 14 reached end of life. If you 
would still like to see this bug fixed and are able to reproduce it 
against a later version of Fedora, you are encouraged to click on 
"Clone This Bug" (top right of this page) and open it against that 
version of Fedora.

Although we aim to fix as many bugs as possible during every release's 
lifetime, sometimes those efforts are overtaken by events.  Often a 
more recent Fedora release includes newer upstream software that fixes 
bugs or makes them obsolete.

The process we are following is described here: 
http://fedoraproject.org/wiki/BugZappers/HouseKeeping