Bug 782483 - Propose that you turn on PrivateTmp=true in service file for bluez
Summary: Propose that you turn on PrivateTmp=true in service file for bluez
Keywords:
Status: CLOSED NOTABUG
Alias: None
Product: Fedora
Classification: Fedora
Component: bluez
Version: rawhide
Hardware: Unspecified
OS: Unspecified
unspecified
unspecified
Target Milestone: ---
Assignee: Bastien Nocera
QA Contact: Fedora Extras Quality Assurance
URL:
Whiteboard:
Depends On:
Blocks: PrivateTmp
TreeView+ depends on / blocked
 
Reported: 2012-01-17 15:28 UTC by Daniel Walsh
Modified: 2012-01-17 21:12 UTC (History)
3 users (show)

Fixed In Version:
Clone Of:
Environment:
Last Closed: 2012-01-17 21:12:37 UTC
Type: ---
Embargoed:


Attachments (Terms of Use)

Description Daniel Walsh 2012-01-17 15:28:37 UTC
I would like to propose using PrivateTmp for bluez, to make it more secure
and avoid users from being able to potentially effect it.

http://fedoraproject.org/wiki/Features/ServicesPrivateTmp

Comment 1 Bastien Nocera 2012-01-17 17:39:46 UTC
It doesn't use temporary files, so I would rather see SELinux denials than papering over the problem.

Comment 2 Daniel Walsh 2012-01-17 21:12:37 UTC
Ok I can remove the label from bluetooth policy and see if they come back.  I was just going through all policy that had tmp_t defined and used init_t.


Note You need to log in before you can comment on or make changes to this bug.