Bug 508459 - SELinux denying synce-hal actions
SELinux denying synce-hal actions
Status: CLOSED WONTFIX
Product: Fedora
Classification: Fedora
Component: selinux-policy-targeted (Show other bugs)
11
All Linux
low Severity medium
: ---
: ---
Assigned To: Miroslav Grepl
Ben Levenson
:
Depends On:
Blocks:
  Show dependency treegraph
 
Reported: 2009-06-27 08:04 EDT by Andri Möll
Modified: 2010-06-28 09:19 EDT (History)
2 users (show)

See Also:
Fixed In Version:
Doc Type: Bug Fix
Doc Text:
Story Points: ---
Clone Of:
Environment:
Last Closed: 2010-06-28 09:19:44 EDT
Type: ---
Regression: ---
Mount Type: ---
Documentation: ---
CRM:
Verified Versions:
Category: ---
oVirt Team: ---
RHEL 7.3 requirements from Atomic Host:
Cloudforms Team: ---


Attachments (Terms of Use)
log output (3.45 KB, text/plain)
2009-06-27 08:05 EDT, Andri Möll
no flags Details
Patrch for F11 (3.23 KB, application/octet-stream)
2009-07-15 15:03 EDT, Daniel Walsh
no flags Details
Denials when plugging the device in (selinux-policy-3.6.12-72.fc11) (1.37 KB, text/plain)
2009-08-14 03:38 EDT, Andri Möll
no flags Details
Denials when using /usr/bin/pls (selinux-policy-3.6.12-72.fc11) (1.02 KB, text/plain)
2009-08-14 03:39 EDT, Andri Möll
no flags Details

  None (edit)
Description Andri Möll 2009-06-27 08:04:18 EDT
Lots of SELinux notifications appear after plugging in a Windows Mobile based phone.  I've attached related seaudit-report output.  Always reproducible.

Related packages:
  synce-hal-0.13.1-3.fc11.x86_64  
  selinux-policy-3.6.12-50.fc11.noarch
  selinux-policy-targeted-3.6.12-50.fc11.noarch
Comment 1 Andri Möll 2009-06-27 08:05:02 EDT
Created attachment 349656 [details]
log output
Comment 2 Christoph Wickert 2009-07-15 14:37:28 EDT
Reassigning to selinux-policy-targeted, so Dan can have a look at this.
Comment 3 Daniel Walsh 2009-07-15 15:03:35 EDT
Created attachment 353881 [details]
Patrch for F11

Miroslav can you add this patch to F11.
Comment 4 Daniel Walsh 2009-07-15 15:04:33 EDT
Andri,

You can add these rules for now using

# grep avc /var/log/audit/audit.log | audit2allow -M mypol
# semodule -i mypol.pp
Comment 5 Miroslav Grepl 2009-07-17 04:55:23 EDT
Fixed in selinux-policy-3.6.12-68.fc11
Comment 6 Andri Möll 2009-07-20 03:47:10 EDT
Thanks, Daniel, for the suggestion.
I'll give the custom audit2allow policy or selinux-policy-3.6.12-68.fc11 a try, whichever comes first.
Comment 7 Andri Möll 2009-08-14 03:36:39 EDT
Some things seem to work (listing and sync-engine), but are still accompanied by numerous access denials.  Did you, Daniel, or someone else give the updated policy a try before releasing?
Comment 8 Andri Möll 2009-08-14 03:38:45 EDT
Created attachment 357399 [details]
Denials when plugging the device in (selinux-policy-3.6.12-72.fc11)
Comment 9 Andri Möll 2009-08-14 03:39:25 EDT
Created attachment 357400 [details]
Denials when using /usr/bin/pls (selinux-policy-3.6.12-72.fc11)
Comment 10 Bug Zapper 2010-04-27 11:17:36 EDT
This message is a reminder that Fedora 11 is nearing its end of life.
Approximately 30 (thirty) days from now Fedora will stop maintaining
and issuing updates for Fedora 11.  It is Fedora's policy to close all
bug reports from releases that are no longer maintained.  At that time
this bug will be closed as WONTFIX if it remains open with a Fedora 
'version' of '11'.

Package Maintainer: If you wish for this bug to remain open because you
plan to fix it in a currently maintained version, simply change the 'version' 
to a later Fedora version prior to Fedora 11's end of life.

Bug Reporter: Thank you for reporting this issue and we are sorry that 
we may not be able to fix it before Fedora 11 is end of life.  If you 
would still like to see this bug fixed and are able to reproduce it 
against a later version of Fedora please change the 'version' of this 
bug to the applicable version.  If you are unable to change the version, 
please add a comment here and someone will do it for you.

Although we aim to fix as many bugs as possible during every release's 
lifetime, sometimes those efforts are overtaken by events.  Often a 
more recent Fedora release includes newer upstream software that fixes 
bugs or makes them obsolete.

The process we are following is described here: 
http://fedoraproject.org/wiki/BugZappers/HouseKeeping
Comment 11 Bug Zapper 2010-06-28 09:19:44 EDT
Fedora 11 changed to end-of-life (EOL) status on 2010-06-25. Fedora 11 is 
no longer maintained, which means that it will not receive any further 
security or bug fix updates. As a result we are closing this bug.

If you can reproduce this bug against a currently maintained version of 
Fedora please feel free to reopen this bug against that version.

Thank you for reporting this bug and we are sorry it could not be fixed.

Note You need to log in before you can comment on or make changes to this bug.