Gentoo Archives: gentoo-hardened

From: Justin Heesemann <jh@××××××.org>
To: gentoo-hardened@l.g.o
Subject: Re: [gentoo-hardened] portage updated, now selinux forbids portage_t.fetch usage of wget
Date: Tue, 22 May 2007 12:07:44
Message-Id: 200705221404.25151.jh@ionium.org
In Reply to: Re: [gentoo-hardened] portage updated, now selinux forbids portage_t.fetch usage of wget by Zac Medico
1 On Tuesday 22 May 2007 04:45:59 Zac Medico wrote:
2 > Justin Heesemann wrote:
3 > > I've just updated portage, (2.1.2.7) and now portage seems unable to
4 > > download anything.
5 > >
6 > > audit(1179767691.954:1414): avc: denied { entrypoint } for pid=26274
7 > > comm="emerge" name="wget" dev=dm-1 ino=17219
8 > > scontext=root:sysadm_r:portage_t.fetch tcontext=system_u:object_r:bin_t
9 > > tclass=file
10 > >
11 > >
12 > > # ls -lZ /usr/bin/wget
13 > > rwxr-xr-x root root system_u:object_r:bin_t
14 > > /usr/bin/wget
15 >
16 > I think the attached patch will solve the problem for you. Could
17 > you test it please?
18 >
19 > Thanks,
20 > Zac
21
22 works for me.
23
24 --
25 Regards,
26 Justin
27 --
28 gentoo-hardened@g.o mailing list