Bug 122969 - /var/run/xdmctl needs to be created as xdm_var_run_t
/var/run/xdmctl needs to be created as xdm_var_run_t
Status: CLOSED RAWHIDE
Product: Fedora
Classification: Fedora
Component: policy (Show other bugs)
rawhide
All Linux
medium Severity medium
: ---
: ---
Assigned To: Daniel Walsh
Ben Levenson
: SELinux
Depends On:
Blocks:
  Show dependency treegraph
 
Reported: 2004-05-10 16:05 EDT by Aleksey Nogin
Modified: 2007-11-30 17:10 EST (History)
2 users (show)

See Also:
Fixed In Version:
Doc Type: Bug Fix
Doc Text:
Story Points: ---
Clone Of:
Environment:
Last Closed: 2004-07-20 08:36:16 EDT
Type: ---
Regression: ---
Mount Type: ---
Documentation: ---
CRM:
Verified Versions:
Category: ---
oVirt Team: ---
RHEL 7.3 requirements from Atomic Host:
Cloudforms Team: ---


Attachments (Terms of Use)

  None (edit)
Description Aleksey Nogin 2004-05-10 16:05:10 EDT
kdm (and may be other dms as well) create names pipes in the
/var/run/xdmctl directory. According to file_contexts, /var/run/xdmctl
is supposed to be xdm_var_run_t (which is the correct thing, IMHO),
but it ends up being created as just var_run_t instead.

I am guessing that something like 

type_transition xdm_t var_run_t:dir xdm_var_run_t;

is needed. (Note that the same thing for :file already exists in
policy.conf).

Another workaround is adding

type_transition xdm_t var_run_t:fifo_file xdm_var_run_t;

which allows creating named pipes in /var/run/xdmctl even when it is
marked var_run_t.
Comment 1 Daniel Walsh 2004-06-02 14:44:29 EDT
Fixed in selinux-policy-strict-1.13.2-7.src.rpm
Comment 2 Daniel Walsh 2004-07-20 08:36:16 EDT
Fixed in Rawhide
Comment 3 Kam Leo 2006-02-12 15:57:26 EST
I'm getting this error with FC4 and selinux-policy-targeted-1.27.1-2.18. Is this
be fixed in targeted?
Comment 4 Kam Leo 2006-02-13 02:51:28 EST
After upgrading a bunch of kde packages which includes
kdebase-3.5.1-1.4.fc4.kde. The message "rm: cannot remove
'/var/run/xdmctl/dmctl' is a directory" no longer appears during boot. File
context for /var/run/xdmctl has not changed it is still var_run_t.
Comment 5 Kam Leo 2006-02-13 03:38:46 EST
My bad. I need to resist immediate updating of bug reports. 

The message "rm: cannot remove '/var/run/xdmctl/dmctl': Is a directory"
reappeared after upgrading the following packages:

xorg-x11-6.8.2-37.FC4.49.2.i386.rpm
xorg-x11-deprecated-libs-6.8.2-37.FC4.49.2.i386.rpm
xorg-x11-deprecated-libs-devel-6.8.2-37.FC4.49.2.i386.rpm
xorg-x11-devel-6.8.2-37.FC4.49.2.i386.rpm
xorg-x11-font-utils-6.8.2-37.FC4.49.2.i386.rpm
xorg-x11-libs-6.8.2-37.FC4.49.2.i386.rpm
xorg-x11-Mesa-libGL-6.8.2-37.FC4.49.2.i386.rpm
xorg-x11-Mesa-libGLU-6.8.2-37.FC4.49.2.i386.rpm
xorg-x11-tools-6.8.2-37.FC4.49.2.i386.rpm
xorg-x11-twm-6.8.2-37.FC4.49.2.i386.rpm
xorg-x11-xauth-6.8.2-37.FC4.49.2.i386.rpm
xorg-x11-xdm-6.8.2-37.FC4.49.2.i386.rpm
xorg-x11-xfs-6.8.2-37.FC4.49.2.i386.rpm

If this bug has been fixed why does this message still occur when KDM is enabled?
Comment 6 Daniel Walsh 2006-02-13 10:01:15 EST
What avc messages are you seeing?

Dan
Comment 7 Kam Leo 2006-02-13 14:10:06 EST
There are no AVC messages in /var/log/audit/audit.log regarding this error. The
error message appears immediately after "Enabling local filesystem quotas" is
displayed which is several processes before auditd is started.
Comment 8 Daniel Walsh 2006-02-15 13:04:53 EST
Is /var/run/xdmctl/dmctl a directory?
Does this happen if you setenforce 0?

If yes then this is not an SELinux problem.
Comment 9 Kam Leo 2006-02-16 03:59:03 EST
1. The file_context for /var/run/xdmctl changed to xdm_var_run_t after upgrading
to selinux-policy-targeted-1.27.1-2.22. So as far as this bug is concerned all
is fixed.

2. /var/run/xdmctl/dmctl is a directory. When selinux=0 is set in grub the error
still occurs. Therefore not a selinux, but a KDM problem. I'll check to see if
it is worthwhile entering a bug with KDE.

Note You need to log in before you can comment on or make changes to this bug.