Gentoo Archives: gentoo-hardened

From: Chris PeBenito <pebenito@g.o>
To: gentoo-hardened@l.g.o
Subject: Re: [gentoo-hardened] SELinux: ENTRYPOINT FAILED for vixie-cron using policy modules 20080525
Date: Mon, 18 Aug 2008 13:11:10
Message-Id: 1219065056.5102.7.camel@defiant.pebenito.net
In Reply to: [gentoo-hardened] SELinux: ENTRYPOINT FAILED for vixie-cron using policy modules 20080525 by Randy Tupas
1 On Sun, 2008-08-17 at 17:58 -0400, Randy Tupas wrote:
2 > I am using selinux on a gentoo desktop, targeted policy (version 22)
3 > with unstable policy modules 20080525. Policycoreutils ebuild version
4 > 1.34.15.
5 >
6 > Since "upgrading", I have been receiving "ENTRYPOINT FAILED" from
7 > vixie-cron.
8 >
9 > Re-emerging vixie-cron does not resolve the problem.
10 >
11 > Changing the type-context of "/var/spool/cron/crontab/username" from
12 > "unconfined_cron_spool_t" to "user_cron_spool_t" allows vixie-cron to
13 > run the crontab. The same applies to root crontabs by changing
14 > "unconfined_cron_spool_t" to "sysadm_cron_spool_t".
15 >
16 > Unfortunately, I receive a lot of avc denials (below):
17 >
18 > Aug 17 14:30:01 tux type=1400 audit(1219008601.354:1507): avc: denied
19 > { read } for pid=23035 comm="sh" name="reports" dev=dm-1 ino=360670
20 > scontext=user_u:user_r:user_crond_t
21 > tcontext=unconfined_u:object_r:unconfined_home_t tclass=dir
22 >
23 > I didn't have this problem when the old default user was "user_u" or
24 > "root", vice "unconfined_u".
25
26 What are the full cron error messages?
27
28 --
29 Chris PeBenito
30 <pebenito@g.o>
31 Developer,
32 Hardened Gentoo Linux
33
34 Public Key: http://pgp.mit.edu:11371/pks/lookup?op=get&search=0xE6AF9243
35 Key fingerprint = B0E6 877A 883F A57A 8E6A CB00 BC8E E42D E6AF 9243

Attachments

File name MIME type
signature.asc application/pgp-signature

Replies