Bug 882623 - Prevent access wine to low memory
Summary: Prevent access wine to low memory
Keywords:
Status: CLOSED CURRENTRELEASE
Alias: None
Product: Fedora
Classification: Fedora
Component: wine
Version: rawhide
Hardware: Unspecified
OS: Unspecified
unspecified
unspecified
Target Milestone: ---
Assignee: Andreas Bierfert
QA Contact: Fedora Extras Quality Assurance
URL:
Whiteboard:
: 665665 964377 964652 965356 (view as bug list)
Depends On:
Blocks:
TreeView+ depends on / blocked
 
Reported: 2012-12-02 11:19 UTC by Mikhail
Modified: 2015-06-23 18:02 UTC (History)
83 users (show)

Fixed In Version:
Clone Of:
Environment:
Last Closed: 2015-06-23 18:02:16 UTC
Type: Bug
Embargoed:


Attachments (Terms of Use)

Description Mikhail 2012-12-02 11:19:29 UTC
Description of problem:
Prevent access wine to low memory

I am very tired of the problems with SE Linux and Wine "SELinux is preventing wine-preloader from 'mmap_zero' accesses on the memprotect"

https://bugzilla.redhat.com/show_bug.cgi?id=870652


Why can't alter Wine for not to use low memory?

Comment 1 Eric Paris 2013-06-07 15:08:12 UTC
*** Bug 965356 has been marked as a duplicate of this bug. ***

Comment 2 Eric Paris 2013-06-07 15:08:14 UTC
*** Bug 964652 has been marked as a duplicate of this bug. ***

Comment 3 Eric Paris 2013-06-07 15:08:17 UTC
*** Bug 964377 has been marked as a duplicate of this bug. ***

Comment 4 Eric Paris 2013-06-07 15:09:55 UTC
*** Bug 665665 has been marked as a duplicate of this bug. ***

Comment 5 Tommy He 2013-07-04 13:35:01 UTC
Description of problem:
Launch CrossOver

Additional info:
reporter:       libreport-2.1.5
hashmarkername: setroubleshoot
kernel:         3.9.8-300.fc19.x86_64
type:           libreport

Comment 6 wspe 2013-07-05 10:14:11 UTC
Description of problem:
I just use "wine" to run "QQ",but the "SELinux" reminds me this problem.
AND I try to "sudo grep wine-preloader /var/log/audit/audit.log | audit2allow -M mypol" to allow it,but the terminal show that "bash: audit2allow: 未找到命令..."......why????? It never happened in old versions

Additional info:
reporter:       libreport-2.1.5
hashmarkername: setroubleshoot
kernel:         3.9.8-300.fc19.x86_64
type:           libreport

Comment 7 Old Uncle 2013-07-05 18:01:20 UTC
Description of problem:
Installed and opened Teamviewer 8.0.17147

Additional info:
reporter:       libreport-2.1.5
hashmarkername: setroubleshoot
kernel:         3.9.8-300.fc19.i686
type:           libreport

Comment 8 Rob 2013-07-10 19:03:51 UTC
On fedora 19
setsebool -P wine_mmap_zero_ignore=1
does not work, selinux stills alert about wine-preloader

Comment 9 nospam 2013-07-12 21:30:46 UTC
Description of problem:
I couldnt repeat the bug
however i was trying to install an game via PlayonLinux script

Additional info:
reporter:       libreport-2.1.5
hashmarkername: setroubleshoot
kernel:         3.9.9-301.fc19.x86_64
type:           libreport

Comment 10 chiwat 2013-07-18 02:36:23 UTC
Description of problem:
install netflix netflix will not work when trying to run for the first time after install

Additional info:
reporter:       libreport-2.1.5
hashmarkername: setroubleshoot
kernel:         3.9.9-302.fc19.x86_64
type:           libreport

Comment 11 Marc Umbricht 2013-07-19 08:55:01 UTC
Description of problem:
installing corefonts with winetricks

Additional info:
reporter:       libreport-2.1.5
hashmarkername: setroubleshoot
kernel:         3.9.9-302.fc19.x86_64
type:           libreport

Comment 12 Robert Xu 2013-07-20 22:29:12 UTC
Description of problem:
Attempting to open any wine application results in an SELinux denial.

Additional info:
reporter:       libreport-2.1.5
hashmarkername: setroubleshoot
kernel:         3.9.9-302.fc19.x86_64
type:           libreport

Comment 13 Marc Umbricht 2013-07-24 02:25:38 UTC
Description of problem:
Ran eve, got error.

Additional info:
reporter:       libreport-2.1.5
hashmarkername: setroubleshoot
kernel:         3.9.9-302.fc19.x86_64
type:           libreport

Comment 14 roxiel 2013-07-29 04:24:35 UTC
Description of problem:
install QQ 2013 with wine

Additional info:
reporter:       libreport-2.1.5
hashmarkername: setroubleshoot
kernel:         3.10.3-300.fc19.i686
type:           libreport

Comment 15 Peter H. Jones 2013-07-30 02:45:55 UTC
Description of problem:
/Trying to run winecfg in wine-1.6-2.fc20.x86_64 on a fc19 system.

Additional info:
reporter:       libreport-2.1.5
hashmarkername: setroubleshoot
kernel:         3.10.3-300.fc19.x86_64
type:           libreport

Comment 16 Enrique 2013-08-07 23:01:48 UTC
Description of problem:
I get a message that reads "New SELinux security alert AVC denial, click icon to view"
When I click the icon it gives me three options to take, the tird one says to report it as a bug.

Additional info:
reporter:       libreport-2.1.6
hashmarkername: setroubleshoot
kernel:         3.10.4-300.fc19.i686
type:           libreport

Comment 17 celio 2013-08-12 08:07:09 UTC
Description of problem:
não sei como aconteceu!

Additional info:
reporter:       libreport-2.1.6
hashmarkername: setroubleshoot
kernel:         3.10.5-201.fc19.x86_64
type:           libreport

Comment 18 gary taylor 2013-08-14 15:22:06 UTC
Description of problem:
I am getting error message for quite sometime, not sure why.

Additional info:
reporter:       libreport-2.1.6
hashmarkername: setroubleshoot
kernel:         3.10.5-201.fc19.x86_64
type:           libreport

Comment 19 Jeff 2013-08-20 15:53:22 UTC
Description of problem:
Installed the lastest wine from fedora's own repo

Additional info:
reporter:       libreport-2.1.6
hashmarkername: setroubleshoot
kernel:         3.10.7-200.fc19.x86_64
type:           libreport

Comment 20 matt.nuechterlein 2013-08-24 18:10:46 UTC
Description of problem:
This happens on boot and several times during runtime. It seems to be access that Teamviewer 8 is trying run.

Additional info:
reporter:       libreport-2.1.6
hashmarkername: setroubleshoot
kernel:         3.10.9-200.fc19.x86_64
type:           libreport

Comment 21 Pavel Roskin 2013-08-28 18:06:34 UTC
Description of problem:
Install wine
Remove ~/.wine
Run winecfg
The "check engine" icon appears in the tray

Additional info:
reporter:       libreport-2.1.6
hashmarkername: setroubleshoot
kernel:         3.10.9-200.fc19.i686
type:           libreport

Comment 22 Pavel Roskin 2013-08-28 18:13:32 UTC
I believe the selinux policy should be changed for Wine until Wine is patched.  I can reproduce the problem with winecfg, which is a utility packaged with Wine.  No Windows executables are involved at all.  So it appears that Wine could do it better.  However, selinux alerts should be reserved for unknown access violations, and this is a known problem.

In my case, the problem is reproduced on a completely up-to-date Fedora 19 system (32-bit i686) with wine-1.7.0-1.fc19

Comment 23 Eric Paris 2013-08-28 18:18:30 UTC
wine is doing something unsafe to support legacy 16bit windows application.  wine will usually function just fine despite this denial.  If you wish to allow it, you may follow the suggestions of the trouble shooter.  If you wish to hide it, (i think) you may also follow those instructions in the troubleshooter.  SELinux is doing the right thing.  Keeping wine from doing performing potentially dangerous operations.  It will not be changed.  The power is yours.

Comment 24 Robert Xu 2013-08-28 18:22:34 UTC
(In reply to Eric Paris from comment #23)
> If you wish to
> allow it, you may follow the suggestions of the trouble shooter.

Well, that's an issue - the suggestions of modifying local policy don't work.

Comment 25 Renich Bon Ciric 2013-08-28 20:31:41 UTC
Description of problem:
I tried using wine to run FileMaker Pro

Additional info:
reporter:       libreport-2.1.6
hashmarkername: setroubleshoot
kernel:         3.10.9-200.fc19.x86_64
type:           libreport

Comment 26 Pavel Roskin 2013-08-28 20:53:47 UTC
(In reply to Eric Paris from comment #23)
I normally disable SELinux after I get tired of the warnings.

I don't think Fedora maintainers should set such low standards.  The software distributed by Fedora (and winecfg is such software) should not trigger SELinux warnings when used in the intended way.

Cannot we have a policy that would disable known unsafe behavior without alerting users?  That may be the best (albeit not ideal) option.

Comment 27 Diego 2013-08-29 20:50:46 UTC
Description of problem:
at startup

Additional info:
reporter:       libreport-2.1.6
hashmarkername: setroubleshoot
kernel:         3.10.9-200.fc19.x86_64
type:           libreport

Comment 28 Yammer 2013-09-02 18:49:05 UTC
Description of problem:
I tried to load the Wine Configuration form the main menu...

Additional info:
reporter:       libreport-2.1.6
hashmarkername: setroubleshoot
kernel:         3.10.10-200.fc19.x86_64
type:           libreport

Comment 29 John 2013-09-03 09:12:42 UTC
Description of problem:
I started Spotify up and Fedora notified me that this problem occured, it does not seem to affect Spotify's operation though.

Additional info:
reporter:       libreport-2.1.6
hashmarkername: setroubleshoot
kernel:         3.10.10-200.fc19.x86_64
type:           libreport

Comment 30 Pavel Roskin 2013-09-03 13:41:30 UTC
After some consideration I came to think that hiding warnings would be bad.  Either Wine should be configured/patched to omit 16-bit support (since we consider it unsafe), or the SELinux policy should allow mmap_zero in wine.

Comment 31 Michael Cronenworth 2013-09-03 13:48:30 UTC
There are many SELinux rules that are hidden from you (dontaudit).

I see three options for this bug but feel free to add more.

1. Add this AVC to don't audit.
2. Open an upstream bug to move low memory support to a non-default configuration flag or remove it entirely.
3. Do nothing.

I'm inclined to do option 2 and ask that OS versions < XP turn on this support but >= XP do not. Since Wine defaults to XP this message would go away for most people.

Comment 32 nospam 2013-09-03 20:55:56 UTC
Description of problem:
Install any game using Playonlinux scripts (i havent tried normal wine but i suspect its the same)
If i remember correctly you should get selinux nmap low memory in kernel
If not try to launch the game in my current configuration i get /usr/bin/wine-preloader should need to mmap low memory everytime
Wine version 1.4.1


Additional info:
reporter:       libreport-2.1.6
hashmarkername: setroubleshoot
kernel:         3.10.9-200.fc19.x86_64
type:           libreport

Comment 33 Joe Zeff 2013-09-15 23:44:57 UTC
Description of problem:
I had just changed the amount of memory DOSBox gives Redneck Rampage from 32 MB to 48, trying to get rid of lag.  (It didn't.)  When I exited the game, I had this alert.  I've played the game before with no trouble, so I don't know if it's the extra memory allocation or what.

Additional info:
reporter:       libreport-2.1.7
hashmarkername: setroubleshoot
kernel:         3.10.11-200.fc19.i686.PAE
type:           libreport

Comment 34 quetzal 2013-09-27 20:39:55 UTC
Description of problem:
When run Wine, it is stoped by SEKinux and it dont work.

Additional info:
reporter:       libreport-2.1.7
hashmarkername: setroubleshoot
kernel:         3.11.1-200.fc19.x86_64
type:           libreport

Comment 35 Alan Orth 2013-09-30 08:06:45 UTC
Description of problem:
I launched wine 1.7.2 with Microsoft Word 2007

Additional info:
reporter:       libreport-2.1.7
hashmarkername: setroubleshoot
kernel:         3.11.1-200.fc19.x86_64
type:           libreport

Comment 36 Cielito 2013-09-30 13:10:39 UTC
Description of problem:
working with wine

Additional info:
reporter:       libreport-2.1.7
hashmarkername: setroubleshoot
kernel:         3.11.1-200.fc19.x86_64
type:           libreport

Comment 37 Chris 2013-09-30 23:34:49 UTC
Description of problem:
I was trying to run teamviewer and was getting this error

Additional info:
reporter:       libreport-2.1.7
hashmarkername: setroubleshoot
kernel:         3.11.1-200.fc19.x86_64
type:           libreport

Comment 38 nino.corsi 2013-10-01 17:57:51 UTC
Description of problem:
Loading a windows application(Corel Draw 11) with wine

Additional info:
reporter:       libreport-2.1.7
hashmarkername: setroubleshoot
kernel:         3.11.1-200.fc19.i686
type:           libreport

Comment 39 Garrett 2013-10-03 05:37:35 UTC
Description of problem:
trying to run Wine at all

Additional info:
reporter:       libreport-2.1.7
hashmarkername: setroubleshoot
kernel:         3.11.2-201.fc19.x86_64
type:           libreport

Comment 40 Chris 2013-10-03 13:56:04 UTC
Description of problem:
can't run wine with out this popping up ...

and if you try the selinux trouble shooters fix you get an error
grep wine-preloader /var/log/audit/audit.log | audit2allow -M mypol
compilation failed:
sh: /usr/bin/checkmodule: No such file or directory

Additional info:
reporter:       libreport-2.1.7
hashmarkername: setroubleshoot
kernel:         3.11.2-201.fc19.x86_64
type:           libreport

Comment 41 Carlo 2013-10-16 03:38:05 UTC
Description of problem:
Dear, when using the wine get the error access SELinux.

Additional info:
reporter:       libreport-2.1.8
hashmarkername: setroubleshoot
kernel:         3.11.4-201.fc19.x86_64
type:           libreport

Comment 42 Tamy 2013-10-16 13:25:44 UTC
Description of problem:
1.- Reboot my lap-top
2.- The system don't start
3.- Only I had seen the logo of fedora
4.- Never start.

Additional info:
reporter:       libreport-2.1.8
hashmarkername: setroubleshoot
kernel:         3.9.5-301.fc19.i686
type:           libreport

Comment 43 Theophanis Kontogiannis 2013-10-21 13:01:01 UTC
Description of problem:
Tried to start Teamviewer8

Additional info:
reporter:       libreport-2.1.8
hashmarkername: setroubleshoot
kernel:         3.11.4-201.fc19.x86_64
type:           libreport

Comment 44 Narayanan B Nair 2013-10-25 08:57:49 UTC
Description of problem:
Teamviewer8

Additional info:
reporter:       libreport-2.1.8
hashmarkername: setroubleshoot
kernel:         3.11.4-201.fc19.x86_64
type:           libreport

Comment 45 Den 2013-10-25 09:46:33 UTC
Description of problem:
Start Wine

Additional info:
reporter:       libreport-2.1.8
hashmarkername: setroubleshoot
kernel:         3.11.6-200.fc19.i686.PAE
type:           libreport

Comment 46 Tiger 2013-10-26 08:39:52 UTC
Description of problem:
by start a game (geheimakte 2 - puritas cordis) with wine

Additional info:
reporter:       libreport-2.1.8
hashmarkername: setroubleshoot
kernel:         3.11.6-200.hu.1.fc19.i686
type:           libreport

Comment 47 Tiger 2013-10-27 15:09:20 UTC
Description of problem:
by start "video cache view" with wine

Additional info:
reporter:       libreport-2.1.8
hashmarkername: setroubleshoot
kernel:         3.11.6-200.hu.1.fc19.i686
type:           libreport

Comment 48 Guido Mazzone 2013-10-30 12:17:46 UTC
Description of problem:
this message appears when I upgrade wine

Additional info:
reporter:       libreport-2.1.8
hashmarkername: setroubleshoot
kernel:         3.11.6-200.fc19.x86_64
type:           libreport

Comment 49 varalda 2013-11-06 12:08:39 UTC
Description of problem:
I installed the team viewer 8 and I tried also the version 9 (beta). When I tried to run it, the bug occured.

Additional info:
reporter:       libreport-2.1.9
hashmarkername: setroubleshoot
kernel:         3.11.6-201.fc19.x86_64
type:           libreport

Comment 50 Almac 2013-11-06 18:16:21 UTC
Description of problem:
Tried to use wine preloader

Additional info:
reporter:       libreport-2.1.8
hashmarkername: setroubleshoot
kernel:         3.11.4-201.fc19.x86_64
type:           libreport

Comment 51 Hamid Salehian 2013-11-14 12:13:32 UTC
Description of problem:
When i run Wine File this error happend on SELinux

Additional info:
reporter:       libreport-2.1.9
hashmarkername: setroubleshoot
kernel:         3.11.7-200.fc19.x86_64
type:           libreport

Comment 52 Mac 2013-11-14 19:31:20 UTC
Description of problem:
Starting Crossover. ABRT complains.

Additional info:
reporter:       libreport-2.1.9
hashmarkername: setroubleshoot
kernel:         3.11.7-200.fc19.x86_64
type:           libreport

Comment 53 Christopher Meng 2013-11-15 09:37:55 UTC
Description of problem:
Tried to run OSU!(a windows music game) and failed.

Terminal said:

[rpmaker@fab SOURCES]$ wine /run/media/rpmaker/XP/Program\ Files/osu\!/osu\!.exe 
err:mscoree:load_mono Could not load Mono into this process

Additional info:
reporter:       libreport-2.1.9
hashmarkername: setroubleshoot
kernel:         3.12.0-1.fc21.i686
type:           libreport

Comment 54 Joe Zeff 2013-11-18 02:57:49 UTC
Description of problem:
I was trying to run an old Windows program to find out if I needed it or not and got this alert.  (As it happens, I don't need it any more and have deleted it.)

Additional info:
reporter:       libreport-2.1.9
hashmarkername: setroubleshoot
kernel:         3.11.8-200.fc19.i686.PAE
type:           libreport

Comment 55 leroy132 2013-11-19 07:14:02 UTC
Description of problem:
when ever click on "open with winehq " this SELinux thing pops up 

Additional info:
reporter:       libreport-2.1.9
hashmarkername: setroubleshoot
kernel:         3.11.8-200.fc19.x86_64
type:           libreport

Comment 56 dogabone 2013-12-04 11:02:45 UTC
Description of problem:
Start the windows steam client in wine. Error happens at startup.

Additional info:
reporter:       libreport-2.1.9
hashmarkername: setroubleshoot
kernel:         3.11.9-200.fc19.x86_64
type:           libreport

Comment 57 OoZooL 2013-12-09 19:25:00 UTC
Description of problem:
I simply installed TeamViwer 9 on Linux with the sudo yum localinstall *.rpm command
and when I initially activated the client the SELinux violation had occurred...

Additional info:
reporter:       libreport-2.1.9
hashmarkername: setroubleshoot
kernel:         3.9.5-301.fc19.x86_64
type:           libreport

Comment 58 cypher 2013-12-21 00:56:33 UTC
Description of problem:
When I tried to start wine

Additional info:
reporter:       libreport-2.1.10
hashmarkername: setroubleshoot
kernel:         3.11.10-200.fc19.x86_64
type:           libreport

Comment 59 Dave Galloway 2014-01-06 10:36:54 UTC
Description of problem:
running wine

Additional info:
reporter:       libreport-2.1.10
hashmarkername: setroubleshoot
kernel:         3.12.6-200.fc19.x86_64
type:           libreport

Comment 60 Yvan Turcot 2014-01-10 17:18:14 UTC
Description of problem:
while installing and attempting to run Lightroom 5 from Adobe

Additional info:
reporter:       libreport-2.1.10
hashmarkername: setroubleshoot
kernel:         3.12.6-200.fc19.x86_64
type:           libreport

Comment 61 Vasil Draganov 2014-01-20 09:20:52 UTC
Description of problem:
This problem appears every time I start Teamviewer v. 9.0.24147 Dev wine-1.6 (latest release).

Additional info:
reporter:       libreport-2.1.10
hashmarkername: setroubleshoot
kernel:         3.12.7-200.fc19.x86_64
type:           libreport

Comment 62 Wilf 2014-11-11 22:07:38 UTC
Description of problem:
Tried opening Safari browser installed under Wine - instead of starting up staright away, got a few AVC denials and the Safari loaded.

Additional info:
reporter:       libreport-2.2.2
hashmarkername: setroubleshoot
kernel:         3.9.5-301.fc19.x86_64
type:           libreport

Comment 63 hx 2015-06-21 14:59:00 UTC
Isn't this fixed by using wine-staging?

Comment 64 Michael Cronenworth 2015-06-23 18:02:16 UTC
No.

Wine has removed this requirement. I no longer see SELinux denials on vanilla wine.


Note You need to log in before you can comment on or make changes to this bug.