Gentoo Archives: gentoo-hardened

From: Tad <tadglines@×××××××.net>
To: 'Chris PeBenito' <pebenito@g.o>
Cc: 'Hardened Gentoo Mail List' <gentoo-hardened@g.o>
Subject: RE: [gentoo-hardened] emerge and setfiles
Date: Tue, 25 Nov 2003 07:02:48
Message-Id: 003a01c3b322$1935ebd0$0301a8c0@sprite
In Reply to: Re: [gentoo-hardened] emerge and setfiles by Chris PeBenito
1 There are no denial messages. From the root:portage_r:portage_t read and
2 getattr /usr/sbin/setfiles but not execute. When I known prohibited action
3 they are logged, but when I try to run setfiles, all I get is "bash:
4 /usr/sbin/setfiles: Permission denied". No "avc: denied" messages in the
5 log.
6
7 I have verified that the /usr/sbin/setfiles context is
8 system_u:object_r:setfiles_exec_t, and that the context of /bin/bash is
9 system_u:object_r:shell_exec_t.
10
11 The permissions on /usr/sbin/setfiles are 755 with root.root ownership.
12
13 I can see nothing wrong so this is really perplexing.
14 What is especially odd is the lack of denial messages.
15
16
17 -Tad
18
19 > -----Original Message-----
20 > From: Chris PeBenito [mailto:pebenito@g.o]
21 > Sent: Monday, November 24, 2003 10:44 PM
22 > To: Tad
23 > Cc: 'Hardened Gentoo Mail List'
24 > Subject: Re: [gentoo-hardened] emerge and setfiles
25 >
26 > On Mon, 2003-11-24 at 21:25, Tad wrote:
27 > > When I emerge a package it fails to run setfiles. It says "permission
28 > > denied". Avc messages appear in the logs. I am doing a "newrole -r
29 >
30 > I'm going to have to see the denial messages to get an idea of whats
31 > going on.
32 >
33 > --
34 > Chris PeBenito
35 > <pebenito@g.o>
36 > Developer,
37 > Hardened Gentoo Linux
38 > Embedded Gentoo Linux
39 >
40 > Public Key: http://pgp.mit.edu:11371/pks/lookup?op=get&search=0xE6AF9243
41 > Key fingerprint = B0E6 877A 883F A57A 8E6A CB00 BC8E E42D E6AF 9243
42
43
44 --
45 gentoo-hardened@g.o mailing list

Replies

Subject Author
RE: [gentoo-hardened] emerge and setfiles Chris PeBenito <pebenito@g.o>