Bug 451877 - unconfined_execmem_exec_t needed for several GHC-built Haskell binaries
unconfined_execmem_exec_t needed for several GHC-built Haskell binaries
Status: CLOSED RAWHIDE
Product: Fedora
Classification: Fedora
Component: selinux-policy (Show other bugs)
rawhide
All Linux
medium Severity medium
: ---
: ---
Assigned To: Daniel Walsh
Fedora Extras Quality Assurance
:
Depends On:
Blocks: 452440
  Show dependency treegraph
 
Reported: 2008-06-17 18:30 EDT by Bryan O'Sullivan
Modified: 2009-06-01 23:58 EDT (History)
5 users (show)

See Also:
Fixed In Version:
Doc Type: Bug Fix
Doc Text:
Story Points: ---
Clone Of:
Environment:
Last Closed: 2009-04-13 10:06:17 EDT
Type: ---
Regression: ---
Mount Type: ---
Documentation: ---
CRM:
Verified Versions:
Category: ---
oVirt Team: ---
RHEL 7.3 requirements from Atomic Host:


Attachments (Terms of Use)

  None (edit)
Description Bryan O'Sullivan 2008-06-17 18:30:45 EDT
The following Haskell programs, built by GHC, need unconfined_execmem_exec_t
added to the SELinux policies:

/usr/bin/haddock
/usr/bin/haddock-0.9
/usr/bin/hasktags
/usr/bin/runghc
/usr/bin/runhaskell
/usr/libexec/ghc-*/ghc-6.8.[0-9]
/usr/libexec/ghc-*/ghc-pkg.bin
/usr/libexec/ghc-*/hsc2hs-bin
Comment 1 Bryan O'Sullivan 2008-06-17 18:33:35 EDT
Tibbs suggests that Haddock doesn't need to be blocked on this.
Comment 2 Daniel Walsh 2008-06-22 06:55:05 EDT
Why doesn't haddock fix their code to not need execmem?

Is this java or mono?

What does haddock need both executable and writeable memory at the same time?
Comment 3 Jens Petersen 2008-06-22 18:59:27 EDT
(In reply to comment #2)
> Is this java or mono?

Haskell ;)
Comment 4 Bryan O'Sullivan 2008-06-22 22:07:40 EDT
The runtime system for programs compiled by GHC generates code dynamically and
executes it.

The interaction with SELinux's enforcing mode is a known problem, which was
previously addressed with a hack: the %post scripts for Haskell programs were
using chcon to add unconfined_exec_mem_t.  This obviously didn't work in lots of
circumstances, hence wanting to apply the policy properly.

The underlying problem, namely the way GHC allocates memory that it intends to
execute dynamically, should be fixed within the next six months or so.  See
http://hackage.haskell.org/trac/ghc/ticket/738 for details.
Comment 5 Daniel Walsh 2008-07-02 13:46:12 EDT
Fixed in selinux-policy-3.3.1-74.fc9.noarch
Comment 6 Bill Nottingham 2008-10-24 16:08:23 EDT
Can Haskell users verify this and close the bug if it's fixed?
Comment 7 Jens Petersen 2009-01-20 19:37:35 EST
I started a comment long ago (which was then lost by a browser crash or restart)...

Basic summary is most (all) haskell programs shipped can run now in enforcing.
However there have been a number of path changes that should probably be updated
in selinux-policy.  I can help to do that.

Currently the changes needed are being done for that at install time.
Comment 8 Daniel Walsh 2009-01-26 11:46:20 EST
What are the paths?
Comment 9 Jens Petersen 2009-06-01 23:57:39 EDT
I tested in F11 and it seems AFAICT the %post stuff we have is no longer needed for ghc executables so I am removing it for f12.

Note You need to log in before you can comment on or make changes to this bug.