Description of problem: SELinux is preventing /usr/bin/ls from 'append' accesses on the file /home/user9/.config/teamviewer8/logfiles/startup.log. ***** Plugin leaks (86.2 confidence) suggests ****************************** If you want to ignore ls trying to append access the startup.log file, because you believe it should not need this access. Then you should report this as a bug. You can generate a local policy module to dontaudit this access. Do # grep /usr/bin/ls /var/log/audit/audit.log | audit2allow -D -M mypol # semodule -i mypol.pp ***** Plugin catchall (14.7 confidence) suggests *************************** If you believe that ls should be allowed append access on the startup.log file by default. Then you should report this as a bug. You can generate a local policy module to allow this access. Do allow this access for now by executing: # grep ls /var/log/audit/audit.log | audit2allow -M mypol # semodule -i mypol.pp Additional Information: Source Context system_u:system_r:initrc_t:s0 Target Context unconfined_u:object_r:config_home_t:s0 Target Objects /home/user9/.config/teamviewer8/logfiles/startup.l og [ file ] Source ls Source Path /usr/bin/ls Port <Unknown> Host (removed) Source RPM Packages coreutils-8.17-8.fc18.x86_64 Target RPM Packages Policy RPM selinux-policy-3.11.1-97.fc18.noarch Selinux Enabled True Policy Type targeted Enforcing Mode Permissive Host Name (removed) Platform Linux (removed) 3.9.4-200.fc18.x86_64 #1 SMP Fri May 24 20:10:49 UTC 2013 x86_64 x86_64 Alert Count 1 First Seen 2013-05-31 09:47:27 PDT Last Seen 2013-05-31 09:47:27 PDT Local ID b12c22b0-294b-41fc-8018-1639361b1489 Raw Audit Messages type=AVC msg=audit(1370018847.767:495): avc: denied { append } for pid=11264 comm="ls" path="/home/user9/.config/teamviewer8/logfiles/startup.log" dev="dm-3" ino=45876364 scontext=system_u:system_r:initrc_t:s0 tcontext=unconfined_u:object_r:config_home_t:s0 tclass=file type=SYSCALL msg=audit(1370018847.767:495): arch=x86_64 syscall=execve success=yes exit=0 a0=e67a60 a1=e33450 a2=e65570 a3=18 items=0 ppid=11249 pid=11264 auid=4294967295 uid=1000 gid=1000 euid=1000 suid=1000 fsuid=1000 egid=1000 sgid=1000 fsgid=1000 ses=4294967295 tty=(none) comm=ls exe=/usr/bin/ls subj=system_u:system_r:initrc_t:s0 key=(null) Hash: ls,initrc_t,config_home_t,file,append audit2allow #============= initrc_t ============== allow initrc_t config_home_t:file append; audit2allow -R require { type initrc_t; } #============= initrc_t ============== gnome_manage_home_config(initrc_t) Additional info: reporter: libreport-2.1.4 hashmarkername: setroubleshoot kernel: 3.9.4-200.fc18.x86_64 type: libreport
Did you try to create an initial policy for /opt/teamviewer8/tv_bin/teamviewerd how I wrote in the previous bug from the last week? I don't see a reason to report these bugs again. Where does teamviewerd come from?
Also # cat myunconfined.te policy_module(myunconfined, 1.0) require{ type initrc_t } unconfined_module(initrc_t) # make -f /usr/share/selinux/devel/Makefile mypol.pp # semodule -i mypol.pp will fix it for now.
*** Bug 969732 has been marked as a duplicate of this bug. ***
*** Bug 969733 has been marked as a duplicate of this bug. ***
*** Bug 969734 has been marked as a duplicate of this bug. ***
*** Bug 969735 has been marked as a duplicate of this bug. ***
*** Bug 969736 has been marked as a duplicate of this bug. ***
*** Bug 969737 has been marked as a duplicate of this bug. ***
*** Bug 969738 has been marked as a duplicate of this bug. ***
*** Bug 969739 has been marked as a duplicate of this bug. ***
*** Bug 969740 has been marked as a duplicate of this bug. ***
*** Bug 969741 has been marked as a duplicate of this bug. ***
*** Bug 969743 has been marked as a duplicate of this bug. ***
*** Bug 969742 has been marked as a duplicate of this bug. ***
*** Bug 969744 has been marked as a duplicate of this bug. ***
*** Bug 969745 has been marked as a duplicate of this bug. ***
*** Bug 969746 has been marked as a duplicate of this bug. ***
*** Bug 969747 has been marked as a duplicate of this bug. ***
*** Bug 969748 has been marked as a duplicate of this bug. ***
*** Bug 969749 has been marked as a duplicate of this bug. ***
*** Bug 969750 has been marked as a duplicate of this bug. ***
*** Bug 969751 has been marked as a duplicate of this bug. ***
*** Bug 969752 has been marked as a duplicate of this bug. ***
There is a bug in the local policy which I posted. -unconfined_module(initrc_t) +unconfined_domain(initrc_t)
(In reply to Miroslav Grepl from comment #1) > Where does teamviewerd come from? http://download.teamviewer.com/download/TeamViewer_Linux_PubKey.asc http://download.teamviewer.com/download/teamviewer_linux.rpm
#============= initrc_t ============== #!!!! This avc is allowed in the current policy allow initrc_t config_home_t:file append;