Hide Forgot
Description of problem: Version-Release number of selected component (if applicable): selinux-policy-targeted-3.7.19-82.el6.noarch selinux-policy-doc-3.7.19-82.el6.noarch selinux-policy-minimum-3.7.19-82.el6.noarch selinux-policy-mls-3.7.19-82.el6.noarch selinux-policy-3.7.19-82.el6.noarch How reproducible: always Steps to Reproduce: 1. get a RHEL-6.1 machine 2. create an user (do not use -Z option when running useradd) 3. log into X Windows as this user 4. run terminal 5. run "sandbox -X firefox" in the terminal 6. click File->Quit in firefox menu Actual results: ---- time->Mon Apr 11 15:40:29 2011 type=SYSCALL msg=audit(1302529229.747:544): arch=40000003 syscall=5 success=no exit=-13 a0=bfa632b0 a1=a0000 a2=0 a3=bfa633a1 items=0 ppid=7556 pid=7578 auid=508 uid=508 gid=509 euid=508 suid=508 fsuid=508 egid=509 sgid=509 fsgid=509 tty=(none) ses=34 comm="firefox" exe="/usr/lib/firefox-3.6/firefox" subj=unconfined_u:unconfined_r:sandbox_x_client_t:s0:c42,c97 key=(null) type=AVC msg=audit(1302529229.747:544): avc: denied { read } for pid=7578 comm="firefox" name="pulse-shm-3243972631" dev=tmpfs ino=126012 scontext=unconfined_u:unconfined_r:sandbox_x_client_t:s0:c42,c97 tcontext=unconfined_u:object_r:user_tmpfs_t:s0 tclass=file ---- time->Mon Apr 11 15:40:29 2011 type=SYSCALL msg=audit(1302529229.752:545): arch=40000003 syscall=102 success=no exit=-13 a0=3 a1=aebff0c0 a2=2983400 a3=0 items=0 ppid=7556 pid=7624 auid=508 uid=508 gid=509 euid=508 suid=508 fsuid=508 egid=509 sgid=509 fsgid=509 tty=(none) ses=34 comm="firefox" exe="/usr/lib/firefox-3.6/firefox" subj=unconfined_u:unconfined_r:sandbox_x_client_t:s0:c42,c97 key=(null) type=AVC msg=audit(1302529229.752:545): avc: denied { name_connect } for pid=7624 comm="firefox" dest=4713 scontext=unconfined_u:unconfined_r:sandbox_x_client_t:s0:c42,c97 tcontext=system_u:object_r:pulseaudio_port_t:s0 tclass=tcp_socket ---- Expected results: no AVCs
Are you seeing any AVC msgs with # sandbox -X -t sandbox_web_t firefox
We are not allwing sandbox_x_t to connect to pulseaudio. Currently firefox needs to run in sandbox_web_t. Milos do you see any value in running firefox without allowing it to connect to the network?