Gentoo Archives: gentoo-hardened

From: Charles WIlliams <sadjehuty@××××××.com>
To: gentoo-hardened@l.g.o
Subject: [gentoo-hardened] Grsecurity Policy Questions
Date: Wed, 05 Sep 2012 03:02:30
Message-Id: 1826241.30F12gWl32@localhost
1 Hey guys,
2
3 This is my first post to the list.
4
5 I've got a KDE-only Hardened Gentoo installed. I've set policy using the
6 learning mode of gradm. However, the policies are a bit too restrictive for my
7 needs.
8
9 My first issue is, I can't delete files from my home directory. The other
10 issue is, I can't access email folders in Kmail, to read emails previously
11 stored.. I get the following error:
12
13 Local Folders: Error while creating item: Unknown error. (NO
14 PartHelperException: Could not open
15 /home/username/.local/share/akonadi/file_db_data/1508_r0 for writing, error
16 was 'Permission denied')
17
18 I did make one slight modification to my home directory in the grsec policy,
19 changing this line, under my username role, from
20
21 /home/username r
22
23 to
24
25 /home/username rw
26
27 I had hoped that one change would allow writing to my home directory, but I
28 get the same error even with this change to the policy file. I am not sure
29 what edits are necessary to the policy file to make it possible to check
30 previously stored emails in Kmail folders or to make it possible to delete
31 files from my home directory.
32
33 I did read the sections on creating policies on the grsecurity website, but it
34 really is beyond what I can understand at this point, although I know it's
35 likely some very small setting I am missing.
36
37 Any help will be appreciated. And thanks to all who've made Hardened Gentoo
38 possible.
39
40 Charles