Bug 697207 - at gdm login ... SELinux is preventing /usr/bin/gok from read access on the directory
Summary: at gdm login ... SELinux is preventing /usr/bin/gok from read access on the d...
Keywords:
Status: CLOSED WONTFIX
Alias: None
Product: Fedora
Classification: Fedora
Component: selinux-policy
Version: 14
Hardware: Unspecified
OS: Unspecified
unspecified
unspecified
Target Milestone: ---
Assignee: Miroslav Grepl
QA Contact: Fedora Extras Quality Assurance
URL:
Whiteboard:
Depends On:
Blocks: 760990
TreeView+ depends on / blocked
 
Reported: 2011-04-16 20:55 UTC by Wendell Baker
Modified: 2012-08-16 14:41 UTC (History)
6 users (show)

Fixed In Version:
Doc Type: Bug Fix
Doc Text:
Clone Of:
: 760990 (view as bug list)
Environment:
Last Closed: 2012-08-16 14:41:19 UTC
Type: ---


Attachments (Terms of Use)
sudo sealert -l 82c72044-db37-4c34-b62c-0fd3f2ca4205 (479 bytes, text/plain)
2011-04-16 20:55 UTC, Wendell Baker
no flags Details
sudo sealert -l 25cfa985-f3d7-4be3-b4ab-4bfc126b7e7b (473 bytes, text/plain)
2011-04-16 20:57 UTC, Wendell Baker
no flags Details
sudo sealert -l 237e8dae-b133-4c66-9c96-54e78f8b1934 (705 bytes, application/octet-stream)
2011-04-16 20:57 UTC, Wendell Baker
no flags Details
sudo sealert -l 384cb886-46a9-4cf7-92d2-d72d9e72ee32 (477 bytes, application/octet-stream)
2011-04-16 20:58 UTC, Wendell Baker
no flags Details

Description Wendell Baker 2011-04-16 20:55:08 UTC
Created attachment 492629 [details]
sudo sealert  -l 82c72044-db37-4c34-b62c-0fd3f2ca4205

Description of problem:

gok seems to need access to some places that selinux doesn't expect

Version-Release number of selected component (if applicable):

$ rpm -q -f /usr/bin/gok
gok-2.30.1-1.fc14.i686


How reproducible:

very

Steps to Reproduce:
1. reboot
2. start up gok (accessibility, on screen keyboard)
3. see messages in /var/log/messages
  
Actual results:

messages ... shown

Expected results:

no messages

Additional info:



from /var/log/messages

Apr 16 13:33:36 pert setroubleshoot: SELinux is preventing /usr/bin/gok from rea
d access on the directory /var/games. For complete SELinux messages. run sealert -l 384cb886-46a9-4cf7-92d2-d72d9e72ee32
Apr 16 13:33:36 pert setroubleshoot: SELinux is preventing /usr/bin/gok from read access on the directory /var/yp. For complete SELinux messages. run sealert -l 237e8dae-b133-4c66-9c96-54e78f8b1934
Apr 16 13:33:37 pert setroubleshoot: SELinux is preventing /usr/bin/gok from read access on the directory /var/www. For complete SELinux messages. run sealert -l 25cfa985-f3d7-4be3-b4ab-4bfc126b7e7b
Apr 16 13:33:37 pert setroubleshoot: SELinux is preventing /usr/bin/gok from read access on the directory /var/racoon. For complete SELinux messages. run sealert -l 82c72044-db37-4c34-b62c-0fd3f2ca4205
Apr 16 13:33:48 pert setroubleshoot: SELinux is preventing /usr/bin/gok from read access on the directory /var/games. For complete SELinux messages. run sealert -l 384cb886-46a9-4cf7-92d2-d72d9e72ee32
Apr 16 13:33:49 pert setroubleshoot: SELinux is preventing /usr/bin/gok from read access on the directory /var/yp. For complete SELinux messages. run sealert -l 237e8dae-b133-4c66-9c96-54e78f8b1934
Apr 16 13:33:49 pert setroubleshoot: SELinux is preventing /usr/bin/gok from read access on the directory /var/www. For complete SELinux messages. run sealert -l 25cfa985-f3d7-4be3-b4ab-4bfc126b7e7b
Apr 16 13:33:50 pert setroubleshoot: SELinux is preventing /usr/bin/gok from read access on the directory /var/racoon. For complete SELinux messages. run sealert -l 82c72044-db37-4c34-b62c-0fd3f2ca4205

Comment 1 Wendell Baker 2011-04-16 20:57:00 UTC
Created attachment 492630 [details]
sudo sealert -l 25cfa985-f3d7-4be3-b4ab-4bfc126b7e7b

Comment 2 Wendell Baker 2011-04-16 20:57:33 UTC
Created attachment 492631 [details]
sudo sealert -l 237e8dae-b133-4c66-9c96-54e78f8b1934

Comment 3 Wendell Baker 2011-04-16 20:58:29 UTC
Created attachment 492632 [details]
sudo sealert -l 384cb886-46a9-4cf7-92d2-d72d9e72ee32

Comment 4 David Zeuthen 2011-12-07 15:47:00 UTC
Can't really do anything about SELinux policy, sorry. Reassigning.

Comment 5 Daniel Walsh 2011-12-07 16:52:16 UTC
David the question here is why is gok listing the contents of /var?  It really has nothing to do with SELinux, other then we have to dontaudit some questionable behaviour.

Comment 6 Fedora End Of Life 2012-08-16 14:41:23 UTC
This message is a notice that Fedora 14 is now at end of life. Fedora 
has stopped maintaining and issuing updates for Fedora 14. It is 
Fedora's policy to close all bug reports from releases that are no 
longer maintained.  At this time, all open bugs with a Fedora 'version'
of '14' have been closed as WONTFIX.

(Please note: Our normal process is to give advanced warning of this 
occurring, but we forgot to do that. A thousand apologies.)

Package Maintainer: If you wish for this bug to remain open because you
plan to fix it in a currently maintained version, feel free to reopen 
this bug and simply change the 'version' to a later Fedora version.

Bug Reporter: Thank you for reporting this issue and we are sorry that 
we were unable to fix it before Fedora 14 reached end of life. If you 
would still like to see this bug fixed and are able to reproduce it 
against a later version of Fedora, you are encouraged to click on 
"Clone This Bug" (top right of this page) and open it against that 
version of Fedora.

Although we aim to fix as many bugs as possible during every release's 
lifetime, sometimes those efforts are overtaken by events.  Often a 
more recent Fedora release includes newer upstream software that fixes 
bugs or makes them obsolete.

The process we are following is described here: 
http://fedoraproject.org/wiki/BugZappers/HouseKeeping


Note You need to log in before you can comment on or make changes to this bug.