Bug 428803 - selinux denials from bluetooth
Summary: selinux denials from bluetooth
Keywords:
Status: CLOSED CURRENTRELEASE
Alias: None
Product: Fedora
Classification: Fedora
Component: bluez-utils
Version: 8
Hardware: All
OS: Linux
low
low
Target Milestone: ---
Assignee: David Woodhouse
QA Contact: Fedora Extras Quality Assurance
URL:
Whiteboard:
Depends On: 429714
Blocks:
TreeView+ depends on / blocked
 
Reported: 2008-01-15 11:51 UTC by Juha Tuomala
Modified: 2008-02-13 05:18 UTC (History)
1 user (show)

Fixed In Version: 3.20-6.fc8
Doc Type: Bug Fix
Doc Text:
Clone Of:
Environment:
Last Closed: 2008-02-13 05:18:38 UTC
Type: ---
Embargoed:


Attachments (Terms of Use)

Description Juha Tuomala 2008-01-15 11:51:06 UTC
Description of problem:

Source Context:  unconfined_u:system_r:bluetooth_t:s0
Target Context:  system_u:object_r:system_crond_var_lib_t:s0
Target Objects:  None [ dir ]
Affected RPM Packages:  
Policy RPM:  selinux-policy-3.0.8-73.fc8
Selinux Enabled:  
TruePolicy Type:  targetedMLS 
Enabled:  
TrueEnforcing Mode:  PermissivePlugin 
Name:  plugins.catchall_fileHost 
Name:  wasa.netnix.ee
Platform:  Linux xxxxxx 2.6.23.8-63.fc8 #1 SMP Wed Nov 21 17:56:40 EST 2007 
x86_64 x86_64
Alert Count:  2
First Seen:  Tue 15 Jan 2008 01:03:13 PM EET
Last Seen:  Tue 15 Jan 2008 01:42:13 PM EET
Local ID:  e9d3278b-3d28-4b4c-bec0-85dc1458107d
Line Numbers:  

Raw Audit Messages 

:avc: denied { search } for comm=hcid dev=sda3 name=misc pid=12058 
scontext=unconfined_u:system_r:bluetooth_t:s0 tclass=dir 
tcontext=system_u:object_r:system_crond_var_lib_t:s0 


Additional info:

I'm running KDE and moving files with konqueror bluetooth:/ sdp plugin

Comment 1 Daniel Walsh 2008-01-15 15:02:00 UTC
Why is hcid searching /var/lib/misc directory?

Comment 2 Bastien Nocera 2008-01-15 15:19:53 UTC
It's one of the possible locations for the oui.txt database which contains
details about vendors depending on the Bluetooth address.

We should probably disable that check, if we knew where that file lives.

Comment 3 Juha Tuomala 2008-01-15 16:00:48 UTC
Is that oui.txt supposed to come from rpm pkgs? If so, it's nowhere in my rpm 
pkgs nor could not 'find' it from /etc /usr nor /var. If f don't ship it, 
perhaps there should be just empty file for it and point to that.

Where it should be statically configured?

Comment 4 Bastien Nocera 2008-01-22 17:05:39 UTC
Filed bug 429714 against hwdata for us to get oui.txt, I'll patch up hcid to
only look wherever hwdata is installing it.

Comment 5 Fedora Update System 2008-01-27 07:20:47 UTC
bluez-utils-3.20-6.fc8 has been pushed to the Fedora 8 testing repository.  If problems still persist, please make note of it in this bug report.
 If you want to test the update, you can install it with 
 su -c 'yum --enablerepo=updates-testing update bluez-utils'.  You can provide feedback for this update here: http://admin.fedoraproject.org/F8/FEDORA-2008-1073

Comment 6 Fedora Update System 2008-02-13 05:18:33 UTC
bluez-utils-3.20-6.fc8 has been pushed to the Fedora 8 stable repository.  If problems still persist, please make note of it in this bug report.


Note You need to log in before you can comment on or make changes to this bug.