Bug 702863 - SELinux is preventing /usr/libexec/mission-control-5 (deleted) from 'connectto' accesses on the unix_stream_socket @/tmp/dbus-uzttIxYXdW.
Summary: SELinux is preventing /usr/libexec/mission-control-5 (deleted) from 'connectt...
Keywords:
Status: CLOSED CURRENTRELEASE
Alias: None
Product: Fedora
Classification: Fedora
Component: selinux-policy
Version: 15
Hardware: x86_64
OS: Linux
unspecified
medium
Target Milestone: ---
Assignee: Miroslav Grepl
QA Contact: Fedora Extras Quality Assurance
URL:
Whiteboard: setroubleshoot_trace_hash:d31677d22d5...
Depends On:
Blocks:
TreeView+ depends on / blocked
 
Reported: 2011-05-07 19:35 UTC by Mathias Teugels
Modified: 2011-05-11 22:11 UTC (History)
2 users (show)

Fixed In Version:
Doc Type: Bug Fix
Doc Text:
Clone Of:
Environment:
Last Closed: 2011-05-11 22:11:02 UTC
Type: ---


Attachments (Terms of Use)

Description Mathias Teugels 2011-05-07 19:35:01 UTC
SELinux is preventing /usr/libexec/mission-control-5 (deleted) from 'connectto' accesses on the unix_stream_socket @/tmp/dbus-uzttIxYXdW.

*****  Plugin catchall (100. confidence) suggests  ***************************

If you believe that mission-control-5 (deleted) should be allowed connectto access on the dbus-uzttIxYXdW unix_stream_socket by default.
Then you should report this as a bug.
You can generate a local policy module to allow this access.
Do
allow this access for now by executing:
# grep mission-control /var/log/audit/audit.log | audit2allow -M mypol
# semodule -i mypol.pp

Additional Information:
Source Context                unconfined_u:unconfined_r:telepathy_mission_contro
                              l_t:s0-s0:c0.c1023
Target Context                unconfined_u:unconfined_r:unconfined_dbusd_t:s0-s0
                              :c0.c1023
Target Objects                @/tmp/dbus-uzttIxYXdW [ unix_stream_socket ]
Source                        mission-control
Source Path                   /usr/libexec/mission-control-5 (deleted)
Port                          <Unknown>
Host                          (removed)
Source RPM Packages           
Target RPM Packages           
Policy RPM                    selinux-policy-3.9.16-21.fc15
Selinux Enabled               True
Policy Type                   targeted
Enforcing Mode                Enforcing
Host Name                     (removed)
Platform                      Linux (removed) 2.6.38.2-9.fc15.x86_64 #1 SMP
                              Wed Mar 30 16:55:57 UTC 2011 x86_64 x86_64
Alert Count                   1
First Seen                    Sat 07 May 2011 09:25:32 PM CEST
Last Seen                     Sat 07 May 2011 09:25:32 PM CEST
Local ID                      e39b64f5-af53-4174-b6ec-3abcafcbf37e

Raw Audit Messages
type=AVC msg=audit(1304796332.186:339): avc:  denied  { connectto } for  pid=1953 comm="mission-control" path=002F746D702F646275732D757A7474497859586457 scontext=unconfined_u:unconfined_r:telepathy_mission_control_t:s0-s0:c0.c1023 tcontext=unconfined_u:unconfined_r:unconfined_dbusd_t:s0-s0:c0.c1023 tclass=unix_stream_socket


type=SYSCALL msg=audit(1304796332.186:339): arch=x86_64 syscall=connect success=yes exit=0 a0=7 a1=7fffa85e1a10 a2=17 a3=0 items=0 ppid=1 pid=1953 auid=500 uid=500 gid=500 euid=500 suid=500 fsuid=500 egid=500 sgid=500 fsgid=500 tty=(none) ses=2 comm=mission-control exe=2F7573722F6C6962657865632F6D697373696F6E2D636F6E74726F6C2D35202864656C6574656429 subj=unconfined_u:unconfined_r:telepathy_mission_control_t:s0-s0:c0.c1023 key=(null)

Hash: mission-control,telepathy_mission_control_t,unconfined_dbusd_t,unix_stream_socket,connectto

audit2allow

#============= telepathy_mission_control_t ==============
allow telepathy_mission_control_t unconfined_dbusd_t:unix_stream_socket connectto;

audit2allow -R

#============= telepathy_mission_control_t ==============
allow telepathy_mission_control_t unconfined_dbusd_t:unix_stream_socket connectto;

Comment 1 Miroslav Grepl 2011-05-11 08:06:09 UTC
If you close Empathy and open it again, are you still getting this?

Comment 2 Mathias Teugels 2011-05-11 08:51:23 UTC
I cannot be sure, I used the above to enable this in selinux, if there's a way to revert this, I'll gladly help.

Comment 3 Miroslav Grepl 2011-05-11 10:52:25 UTC
You can disable your local policy using

# semodule -d mypol.pp


and then enable using

# semodule -e mypol.pp



Or remove using

# semodule -r mypol.pp

Comment 4 Mathias Teugels 2011-05-11 11:17:05 UTC
Disabled "mypol" using:

# semodule -d mypol

Adding the .pp made semodule not find the policy.

Checked using:

# semodule -l | grep mypol
mypol	1.0	Disabled

Closed empathy and reopened. Don't see any abrt or selinux messages yet.

Just to be sure, I killed the mission-control-5, reopened empathy, checked mission-control-5 running, and no messages as of yet.

Comment 5 Daniel Walsh 2011-05-11 22:11:02 UTC
Indicating that the fix worked.


Note You need to log in before you can comment on or make changes to this bug.