Gentoo Archives: gentoo-hardened

From: Hinnerk van Bruinehsen <h.v.bruinehsen@×××××××××.de>
To: gentoo-hardened@l.g.o
Subject: Re: [gentoo-hardened] Gnome wrong Selinux user role.
Date: Mon, 27 Feb 2012 21:57:57
Message-Id: 4F4BFC3B.5030109@fu-berlin.de
In Reply to: Re: [gentoo-hardened] Gnome wrong Selinux user role. by Sven Vermeulen
1 -----BEGIN PGP SIGNED MESSAGE-----
2 Hash: SHA1
3
4 On 27.02.2012 21:15, Sven Vermeulen wrote:
5 > On Mon, Feb 27, 2012 at 09:53:41PM +0200, Cor Legmaat wrote:
6 >>>> This is what I get with gnome-terminal:
7 >>>>> cor@k53s ~ $ id -Z system_u:system_r:initrc_t cor@k53s ~ $
8 >>>>> ssh 127.0.0.1 Last login: Mon Feb 27 20:01:41 SAST 2012
9 >>>>> from k53s.cor.za.net on pts/1 cor@k53s ~ $ id -Z
10 >>>>> staff_u:staff_r:staff_t
11 > [...]
12 >
13 > Hmm, being in initrc_t isn't correct either; I'd at least expect it
14 > to be xdm_t.
15 >
16 > Can you check the file context of your gdm binary?
17 >
18 > ~# ls -Z /usr/sbin/gdm
19 >
20 > It should be xdm_exec_t (yes, xdm_exec_t, not gdm_exec_t). If not,
21 > set it that way (and tell me which path the binary is at so I can
22 > update the policy).
23 >
24 > ~# chcon -t xdm_exec_t /usr/sbin/gdm
25 >
26 > If the system complains about an unknown type, make sure you have
27 > the xserver module loaded:
28 >
29 > ~# emerge selinux-xserver ~# semodule -l | grep xserver ~# rlpkg
30 > gdm ~# ls -Z /usr/sbin/gdm
31 >
32 > Wkr, Sven Vermeulen
33 >
34
35 If have had problems with this myself. Making pam_selinux.so required
36 in the gdm pam file changed it for me most of the time.
37 Sometimes I seem to hit some kind of race condition though which
38 requires me to restart xdm before getting the right context. It's kind
39 of anoying...
40
41 -----BEGIN PGP SIGNATURE-----
42 Version: GnuPG v2.0.18 (GNU/Linux)
43 Comment: Using GnuPG with Mozilla - http://enigmail.mozdev.org/
44
45 iQEcBAEBAgAGBQJPS/w7AAoJEJwwOFaNFkYc598H/1BRHhw7DdQcEKlzJ/btqAhv
46 Lx362lccBtv78JAVVuPJnE0Al+/IpKecPfB3/YVYi+x9Yg6rENqUaeGXsVvBuarh
47 5lWFgzV7O+AXvgI3kc7cXfG27joiWdOZ2BMd3BRv3aZ+5H+pqzwPBmeI6jightGI
48 EK9TO/FWnCcEeKnAzlY3nbIfwZMuIYIKTp2csLdCFYf6TaYrSJJz+SeIGUUh/QeA
49 WmHJp4Vydtm1JhIK3ceRZ9fPDzcQnDqZEUj38jB9rGtqPl4aeq25ofdP4svpr26n
50 zLCFJo3/CeVB0kRglbaVFrmVwKYHzdFauWoHB4zS7TK8nBYbrMq1KcHssQeAiQw=
51 =NxbC
52 -----END PGP SIGNATURE-----

Replies

Subject Author
Re: [gentoo-hardened] Gnome wrong Selinux user role. Cor Legmaat <cor@××××××.net>