1 |
There are no denial messages. From the root:portage_r:portage_t read and |
2 |
getattr /usr/sbin/setfiles but not execute. When I known prohibited action |
3 |
they are logged, but when I try to run setfiles, all I get is "bash: |
4 |
/usr/sbin/setfiles: Permission denied". No "avc: denied" messages in the |
5 |
log. |
6 |
|
7 |
I have verified that the /usr/sbin/setfiles context is |
8 |
system_u:object_r:setfiles_exec_t, and that the context of /bin/bash is |
9 |
system_u:object_r:shell_exec_t. |
10 |
|
11 |
The permissions on /usr/sbin/setfiles are 755 with root.root ownership. |
12 |
|
13 |
I can see nothing wrong so this is really perplexing. |
14 |
What is especially odd is the lack of denial messages. |
15 |
|
16 |
|
17 |
-Tad |
18 |
|
19 |
> -----Original Message----- |
20 |
> From: Chris PeBenito [mailto:pebenito@g.o] |
21 |
> Sent: Monday, November 24, 2003 10:44 PM |
22 |
> To: Tad |
23 |
> Cc: 'Hardened Gentoo Mail List' |
24 |
> Subject: Re: [gentoo-hardened] emerge and setfiles |
25 |
> |
26 |
> On Mon, 2003-11-24 at 21:25, Tad wrote: |
27 |
> > When I emerge a package it fails to run setfiles. It says "permission |
28 |
> > denied". Avc messages appear in the logs. I am doing a "newrole -r |
29 |
> |
30 |
> I'm going to have to see the denial messages to get an idea of whats |
31 |
> going on. |
32 |
> |
33 |
> -- |
34 |
> Chris PeBenito |
35 |
> <pebenito@g.o> |
36 |
> Developer, |
37 |
> Hardened Gentoo Linux |
38 |
> Embedded Gentoo Linux |
39 |
> |
40 |
> Public Key: http://pgp.mit.edu:11371/pks/lookup?op=get&search=0xE6AF9243 |
41 |
> Key fingerprint = B0E6 877A 883F A57A 8E6A CB00 BC8E E42D E6AF 9243 |
42 |
|
43 |
|
44 |
-- |
45 |
gentoo-hardened@g.o mailing list |