Bug 474281 - SELinux prevents Firefox from executing RealPlayer plugin
SELinux prevents Firefox from executing RealPlayer plugin
Product: Fedora
Classification: Fedora
Component: selinux-policy (Show other bugs)
i686 Linux
low Severity medium
: ---
: ---
Assigned To: Daniel Walsh
Fedora Extras Quality Assurance
Depends On:
  Show dependency treegraph
Reported: 2008-12-02 23:13 EST by Juan
Modified: 2009-11-18 05:33 EST (History)
3 users (show)

See Also:
Fixed In Version:
Doc Type: Bug Fix
Doc Text:
Story Points: ---
Clone Of:
Last Closed: 2009-11-18 05:33:54 EST
Type: ---
Regression: ---
Mount Type: ---
Documentation: ---
Verified Versions:
Category: ---
oVirt Team: ---
RHEL 7.3 requirements from Atomic Host:
Cloudforms Team: ---

Attachments (Terms of Use)
Copy of the selinux alert (3.03 KB, text/plain)
2008-12-02 23:13 EST, Juan
no flags Details
SELinux alert file for one of Adobe Reader files (3.25 KB, text/plain)
2008-12-03 19:33 EST, Juan
no flags Details

  None (edit)
Description Juan 2008-12-02 23:13:00 EST
Created attachment 325476 [details]
Copy of the selinux alert

Description of problem:
I have Fedora 10 with all on-line updates applied.
I installed RealPlayer 11 and now, everytime I started firefox, I got a message from selinux, preventing npviewer.bin (nsplugin_t) from executing /opt/real/RealPlayer/mozilla/nphelix.so.
As suggested in the message, I executed chcon -t bin_t '/opt/real/RealPlayer/mozilla/nphelix.so' and that fixed the problem.
Then I executed semanage fcontext -a -t bin_t '/opt/real/RealPlayer/mozilla/nphelix.so', as also suggested by the message.

Version-Release number of selected component (if applicable):
RealPlayer (GOLD)

How reproducible:
With the given versions installed, just start firefox, and a message will appear in the problem navigator informing of the problem.

Steps to Reproduce:
1. Install the versions given
2. Start Firefox

Actual results:
Message from selinux preventing the execution of the plugin

Expected results:
The plugin is loaded without any problem and no message from selinux appears

Additional info:
Comment 1 Juan 2008-12-03 19:33:27 EST
Created attachment 325613 [details]
SELinux alert file for one of Adobe Reader files
Comment 2 Juan 2008-12-03 19:35:27 EST
The same happens about Adobe Reader plugin.
I get the same error for all /opt/Adobe/Reader8/Reader/intellinux/sidecars/*.ESP files.
The version of the Reader is:
AdobeReader_esp-8.1.3-1 (i486)

The new (updated today) version of selinux-policy is:

Firefox version is the same.
The solution for the problem has been the same as in the case of Real Player, but applied to every of the .ESP files in that directory.

I attach one of the selinux alert file, for one of the ESP files.
Comment 3 Daniel Walsh 2008-12-04 09:16:28 EST
/opt/real/RealPlayer/mozilla/nphelix.so  should be labeled lib_t, if you run restorecon on it, it will get relabeled.

I will fix the labeling on adobe.

Also you can turn off the confinement of nsplugin, if it is causing you problems.

# setsebool -P allow_unconfined_nsplugin_transition 0
Then restart firefox, it should work then.

I am changing the default since this is happening to too many people.

Fixed in selinux-policy-3.5.13-31.fc10
Comment 4 Bug Zapper 2009-11-18 05:17:27 EST
This message is a reminder that Fedora 10 is nearing its end of life.
Approximately 30 (thirty) days from now Fedora will stop maintaining
and issuing updates for Fedora 10.  It is Fedora's policy to close all
bug reports from releases that are no longer maintained.  At that time
this bug will be closed as WONTFIX if it remains open with a Fedora 
'version' of '10'.

Package Maintainer: If you wish for this bug to remain open because you
plan to fix it in a currently maintained version, simply change the 'version' 
to a later Fedora version prior to Fedora 10's end of life.

Bug Reporter: Thank you for reporting this issue and we are sorry that 
we may not be able to fix it before Fedora 10 is end of life.  If you 
would still like to see this bug fixed and are able to reproduce it 
against a later version of Fedora please change the 'version' of this 
bug to the applicable version.  If you are unable to change the version, 
please add a comment here and someone will do it for you.

Although we aim to fix as many bugs as possible during every release's 
lifetime, sometimes those efforts are overtaken by events.  Often a 
more recent Fedora release includes newer upstream software that fixes 
bugs or makes them obsolete.

The process we are following is described here: 

Note You need to log in before you can comment on or make changes to this bug.