Gentoo Archives: gentoo-hardened

From: Randy Tupas <rjtupas@×××××××.com>
To: "gentoo-hardened@g.o" <gentoo-hardened@l.g.o>
Subject: [gentoo-hardened] SELinux: ENTRYPOINT FAILED for vixie-cron using policy modules 20080525
Date: Sun, 17 Aug 2008 21:58:38
Message-Id: BAY101-W4884BCEEC62C3129901F6B46F0@phx.gbl
1 I am using selinux on a gentoo desktop, targeted policy (version 22) with unstable policy modules 20080525. Policycoreutils ebuild version 1.34.15.
2
3 Since "upgrading", I have been receiving "ENTRYPOINT FAILED" from vixie-cron.
4
5 Re-emerging vixie-cron does not resolve the problem.
6
7 Changing the type-context of "/var/spool/cron/crontab/username" from "unconfined_cron_spool_t" to "user_cron_spool_t" allows vixie-cron to run the crontab. The same applies to root crontabs by changing "unconfined_cron_spool_t" to "sysadm_cron_spool_t".
8
9 Unfortunately, I receive a lot of avc denials (below):
10
11 Aug 17 14:30:01 tux type=1400 audit(1219008601.354:1507): avc: denied { read } for pid=23035 comm="sh" name="reports" dev=dm-1 ino=360670 scontext=user_u:user_r:user_crond_t tcontext=unconfined_u:object_r:unconfined_home_t tclass=dir
12
13 I didn't have this problem when the old default user was "user_u" or "root", vice "unconfined_u".
14
15 Any suggestions??
16
17 _________________________________________________________________
18 Talk to your Yahoo! Friends via Windows Live Messenger. Find out how.
19 http://www.windowslive.com/explore/messenger?ocid=TXT_TAGLM_WL_messenger_yahoo_082008

Replies