Bug 460129 - fix policy for various packages
Summary: fix policy for various packages
Keywords:
Status: CLOSED RAWHIDE
Alias: None
Product: Fedora
Classification: Fedora
Component: selinux-policy
Version: rawhide
Hardware: All
OS: Linux
medium
medium
Target Milestone: ---
Assignee: Daniel Walsh
QA Contact: Fedora Extras Quality Assurance
URL:
Whiteboard:
Depends On:
Blocks:
TreeView+ depends on / blocked
 
Reported: 2008-08-26 11:13 UTC by Dominick Grift
Modified: 2008-09-08 20:30 UTC (History)
2 users (show)

Fixed In Version:
Doc Type: Bug Fix
Doc Text:
Clone Of:
Environment:
Last Closed: 2008-09-08 20:30:20 UTC
Type: ---
Embargoed:


Attachments (Terms of Use)
various policy (9.88 KB, text/plain)
2008-08-26 11:14 UTC, Dominick Grift
no flags Details

Description Dominick Grift 2008-08-26 11:13:24 UTC
Description of problem:

    Add prelude_correlator policy to prelude domain.
    Add PADS daemon domain.
    Fix some policy in prelude domain.
    Fix some policy in snort domain.
    Fix some policy in postgresql domain.
    Fix contexts in amavisd domain.


Version-Release number of selected component (if applicable):
3.5.4-2.fc10

Additional info:

Please see attached patch.

Comment 1 Dominick Grift 2008-08-26 11:14:43 UTC
Created attachment 314977 [details]
various policy

Comment 2 Dominick Grift 2008-08-26 11:20:06 UTC
There is one issue with PADS. By default it manages a file in /etc. (/etc/pads-assets.csv)

This required me to give pads manage_file_perms for files in etc labeled pads_config_t.

I could may split this in PADS file that can only be read in /etc and PADS a file that can be fully manage by PADS.

Comment 3 Daniel Walsh 2008-08-28 12:53:36 UTC
Try to get PADS to fix this by moving it to a different directory /var/lib/pads or /var/run/pads/

You can create a pads_etc_rw_t

filess_etc_filetrans(pads_t, pads_etc_rw_t, file)

Comment 4 Daniel Walsh 2008-09-08 20:30:02 UTC
Fixed in selinux-policy-3.5.7-1.fc10.noarch

I think your labeling on /etc/pads* is incorrect.


Note You need to log in before you can comment on or make changes to this bug.