Bug 119786 - Numerous programs fail to access xauth file in /tmp
Summary: Numerous programs fail to access xauth file in /tmp
Keywords:
Status: CLOSED RAWHIDE
Alias: None
Product: Fedora
Classification: Fedora
Component: policy
Version: rawhide
Hardware: All
OS: Linux
medium
high
Target Milestone: ---
Assignee: Daniel Walsh
QA Contact: Ben Levenson
URL:
Whiteboard:
Depends On:
Blocks:
TreeView+ depends on / blocked
 
Reported: 2004-04-02 06:38 UTC by Aleksey Nogin
Modified: 2007-11-30 22:10 UTC (History)
1 user (show)

Fixed In Version:
Doc Type: Bug Fix
Doc Text:
Clone Of:
Environment:
Last Closed: 2004-04-08 03:41:26 UTC
Type: ---
Embargoed:


Attachments (Terms of Use)

Description Aleksey Nogin 2004-04-02 06:38:11 UTC
xauth creates temporary files in the /tmp dir, but currently it is not
permitted to do so:

audit(1080888006.766:0): avc:  denied  { write } for  pid=2730
exe=/usr/X11R6/bin/xauth name=tmp dev=hda2 ino=212577
scontext=aleksey:staff_r:staff_xauth_t
tcontext=system_u:object_r:tmp_t tclass=dir
audit(1080888008.770:0): avc:  denied  { write } for  pid=2730
exe=/usr/X11R6/bin/xauth name=tmp dev=hda2 ino=212577
scontext=aleksey:staff_r:staff_xauth_t
tcontext=system_u:object_r:tmp_t tclass=dir
audit(1080888010.776:0): avc:  denied  { write } for  pid=2730
exe=/usr/X11R6/bin/xauth name=tmp dev=hda2 ino=212577
scontext=aleksey:staff_r:staff_xauth_t
tcontext=system_u:object_r:tmp_t tclass=dir

Comment 1 Aleksey Nogin 2004-04-02 07:15:27 UTC
I, not I see more exactly what is happaning. As a part of work on bug
119204, the xauth data was forced to be relocated to /tmp instead of
using the $HOME/.Xauthority. The authority file ends up being marked
as xdm_tmp_t and this causes huge problems - xauth can not read it,
ssh can not read it, mozilla can not read it...

Comment 2 Daniel Walsh 2004-04-06 03:05:46 UTC
This should be fixed with the latest updates to gdm and policy.  xauth
is created in homedir and xsession-errors is in /tmp


Comment 3 Aleksey Nogin 2004-04-08 03:21:33 UTC
Confirming that this WFM with xinitrc-3.39-1 (I am using kdm) and
policy-sources-1.9.2-12



Note You need to log in before you can comment on or make changes to this bug.