Bug 468318 - SELinux is preventing updatedb (locate_t) "getattr" to /mnt/hgfs (unlabeled_t).
Summary: SELinux is preventing updatedb (locate_t) "getattr" to /mnt/hgfs (unlabeled_t).
Keywords:
Status: CLOSED RAWHIDE
Alias: None
Product: Fedora
Classification: Fedora
Component: selinux-policy
Version: rawhide
Hardware: x86_64
OS: Linux
medium
medium
Target Milestone: ---
Assignee: Daniel Walsh
QA Contact: Fedora Extras Quality Assurance
URL:
Whiteboard:
Depends On:
Blocks:
TreeView+ depends on / blocked
 
Reported: 2008-10-24 03:40 UTC by dynmosaic
Modified: 2008-10-27 20:28 UTC (History)
4 users (show)

Fixed In Version:
Doc Type: Bug Fix
Doc Text:
Clone Of:
Environment:
Last Closed: 2008-10-24 12:34:49 UTC
Type: ---
Embargoed:


Attachments (Terms of Use)

Description dynmosaic 2008-10-24 03:40:33 UTC
Description of problem:
SELinux denied access requested by updatedb. It is not expected that this access is required by updatedb and this access may signal an intrusion attempt. It is also possible that the specific version or configuration of the application is causing it to require additional access. 

Version-Release number of selected component (if applicable):
Source Context:  system_u:system_r:locate_t:s0
Target Context:  system_u:object_r:unlabeled_t:s0
Target Objects:  /mnt/hgfs [ dir ]
Source:  updatedb
Source Path:  /usr/bin/updatedb
Port:  <Unknown>
Host:  fedora
Source RPM Packages:  mlocate-0.21-1.fc10
Target RPM Packages:  
Policy RPM:  selinux-policy-3.5.13-4.fc10
Selinux Enabled:  True
Policy Type:  targeted
MLS Enabled:  True
Enforcing Mode:  Enforcing
Plugin Name:  catchall_file
Host Name:  fedora
Platform:  Linux fedora 2.6.27.3-39.fc10.x86_64 #1 SMP Wed Oct 22 21:04:28 EDT 2008 x86_64 x86_64


How reproducible:
running fedora rawhide 64bits inside vmware workstation 6.5 on a vista host with share enabled to allow access of host files from fedora guest. 
vmware-tools are compiled and installed.

Steps to Reproduce:
1. cp something to /mnt/hgfs/Downloads
2.
3.
  
Actual results:
[root@fedora ~]# cp .bashrc  /mnt/hgfs/Downloads/
cp: cannot create regular file `/mnt/hgfs/Downloads/.bashrc': Permission denied

Expected results:


Additional info

Comment 1 Daniel Walsh 2008-10-24 12:34:49 UTC
Fixed in selinux-policy-3.5.13-7.fc10

Comment 2 dynmosaic 2008-10-27 20:28:50 UTC
Fix verified in selinux-policy-3.5.13-8.fc10. Thanks for your quick fix.


Note You need to log in before you can comment on or make changes to this bug.