Gentoo Websites Logo
Go to: Gentoo Home Documentation Forums Lists Bugs Planet Store Wiki Get Gentoo!
Bug 217463 - sec-policy/selinux-samba-20070928 prevent the clients from mounting samba shares
Summary: sec-policy/selinux-samba-20070928 prevent the clients from mounting samba shares
Status: RESOLVED INVALID
Alias: None
Product: Gentoo Linux
Classification: Unclassified
Component: Hardened (show other bugs)
Hardware: All Linux
: High major (vote)
Assignee: SE Linux Bugs
URL:
Whiteboard:
Keywords:
Depends on:
Blocks:
 
Reported: 2008-04-12 22:20 UTC by GNUtoo
Modified: 2008-04-15 20:32 UTC (History)
0 users

See Also:
Package list:
Runtime testing required: ---


Attachments

Note You need to log in before you can comment on or make changes to this bug.
Description GNUtoo 2008-04-12 22:20:32 UTC
it's annoying because evrytime i want to share something i have to desactivate selinux...
here are the avc denials:
audit(1208040218.783:325): enforcing=0 old_enforcing=1 auid=4294967295
audit(1208040260.070:326): avc:  denied  { append } for  pid=8021 comm="smbd" name="log.smbd" dev=md3 ino=17580044 scontext=user_u:system_r:smbd_t tcontext=system_u:object_r:samba_log_t tclass=file
audit(1208040293.135:327): avc:  denied  { search } for  pid=8044 comm="smbd" name="home" dev=md3 ino=16711681 scontext=user_u:system_r:smbd_t tcontext=system_u:object_r:home_root_t tclass=dir
audit(1208040293.135:328): avc:  denied  { search } for  pid=8044 comm="smbd" name="dev" dev=md3 ino=4407370 scontext=user_u:system_r:smbd_t tcontext=user_u:object_r:user_home_t tclass=dir
audit(1208040293.135:329): avc:  denied  { getattr } for  pid=8044 comm="smbd" path="/home/gentux/dev/perl/dailymotion" dev=md3 ino=4477896 scontext=user_u:system_r:smbd_t tcontext=user_u:object_r:user_home_t tclass=dir

of course i used run_init to run /etc/init.d/samba start


Reproducible: Always




# emerge --info
 * Overlay eclasses override eclasses from PORTDIR:
 *
 *   '/usr/portage/local/layman/java-gcj-overlay/eclass/java-osgi.eclass'
 *   '/usr/portage/local/layman/java-gcj-overlay/eclass/java-pkg-2.eclass'
 *   '/usr/portage/local/layman/java-gcj-overlay/eclass/java-pkg-opt-2.eclass'
 *   '/usr/portage/local/layman/java-gcj-overlay/eclass/java-utils-2.eclass'
 *   '/usr/portage/local/layman/kde/eclass/kde4-base.eclass'
 *   '/usr/portage/local/layman/kde/eclass/kde4-functions.eclass'
 *   '/usr/portage/local/layman/kde/eclass/kde4-meta.eclass'
 *   '/usr/overlay/eclass/mercurial.eclass'
 *
 * It is best to avoid overridding eclasses from PORTDIR because it will
 * trigger invalidation of cached ebuild metadata that is distributed with
 * the portage tree. If you must override eclasses from PORTDIR then you
 * are advised to run `emerge --regen` after each time that you run `emerge
 * --sync`. Set PORTAGE_ECLASS_WARNING_ENABLE="0" in /etc/make.conf if you
 * would like to disable this warning.
Portage 2.1.4.4 (selinux/2007.0/x86, gcc-4.2.2, glibc-2.6.1-r0, 2.6.24-gentoo-r2_port4 i686)
=================================================================
System uname: 2.6.24-gentoo-r2_port4 i686 Intel(R) Pentium(R) M processor 2.00GHz
Timestamp of tree: Sat, 12 Apr 2008 21:30:01 +0000
distcc 2.18.3 i686-pc-linux-gnu (protocols 1 and 2) (default port 3632) [disabled]
ccache version 2.4 [disabled]
app-shells/bash:     3.2_p17-r1
dev-java/java-config: 1.3.7, 2.1.4
dev-lang/python:     2.3.6-r4, 2.4.4-r6, 2.5.1-r4
dev-python/pycrypto: 2.0.1-r6
dev-util/ccache:     2.4-r7
sys-apps/baselayout: 1.12.11.1
sys-apps/sandbox:    1.2.18.1-r2
sys-devel/autoconf:  2.13, 2.61-r1
sys-devel/automake:  1.4_p6, 1.5, 1.6.3, 1.7.9-r1, 1.8.5-r3, 1.9.6-r2, 1.10
sys-devel/binutils:  2.18-r1
sys-devel/gcc-config: 1.4.0-r4
sys-devel/libtool:   1.5.26
virtual/os-headers:  2.6.23-r3
ACCEPT_KEYWORDS="x86"
CBUILD="i686-pc-linux-gnu"
CFLAGS="-O2 -march=pentium-m -pipe"
CHOST="i686-pc-linux-gnu"
CONFIG_PROTECT="/etc /usr/kde/3.5/env /usr/kde/3.5/share/config /usr/kde/3.5/shutdown /usr/share/config /var/bind"
CONFIG_PROTECT_MASK="/etc/env.d /etc/env.d/java/ /etc/fonts/fonts.conf /etc/gconf /etc/php/apache2-php5/ext-active/ /etc/php/cgi-php5/ext-active/ /etc/php/cli-php5/ext-active/ /etc/revdep-rebuild /etc/terminfo /etc/texmf/web2c /etc/udev/rules.d"
CXXFLAGS="-O2 -march=pentium-m -pipe"
DISTDIR="/usr/portage/distfiles"
FEATURES="distlocks loadpolicy metadata-transfer nostrip parallel-fetch sandbox selinux sesandbox sfperms strict unmerge-orphans userfetch"
GENTOO_MIRRORS="http://distfiles.gentoo.org http://distro.ibiblio.org/pub/linux/distributions/gentoo"
LANG="en_US.utf8"
LC_ALL="en_US.utf8"
LINGUAS="en en_GB en_US"
MAKEOPTS="-j2"
PKGDIR="/usr/portage/packages"
PORTAGE_RSYNC_OPTS="--recursive --links --safe-links --perms --times --compress --force --whole-file --delete --stats --timeout=180 --exclude=/distfiles --exclude=/local --exclude=/packages"
PORTAGE_TMPDIR="/var/tmp"
PORTDIR="/usr/portage"
PORTDIR_OVERLAY="/usr/overlay /usr/portage/local/layman/pro-audio /usr/portage/local/layman/sunrise /usr/portage/local/layman/custom-kernels /usr/portage/local/layman/java-overlay /usr/portage/local/layman/java-gcj-overlay /usr/portage/local/layman/zugaina /usr/portage/local/layman/kde /usr/overlay"
SYNC="rsync://rsync.gentoo.org/gentoo-portage"
USE="7zip X a52 aac acl acpi adns aiglx alsa amr apache2 asf bash-completion berkdb bl blender-game bluetooth branding cdda cddb cdparanoia chardet clearcase cli contrarius cracklib cran crypt css cups cvs dbus dga dia divx dri dts dv dvb dvd dvdnav dvdr dvdread editor effects enca encode examples exif expat fam fat ffmpeg firefox flac foomaticdb fping fuse gcj gdbm gif gimp gimpprint glsa gmedia gnutls gpm gstreamer gtk hfs httpd iconv ieee1394 imagemagick inkjar inquisitio irmc isdnlog jabber jfs jpeg jpeg2k kde kerberos kqemu lcms ldap libnotify lzo mad maps matroska midi mikmod mjpeg mmx mmxext mng modplug mp2 mp3 mp4 mpi mplayer mudflap musepack ncurses nfs nptl nptlonly nsplugin ntfs ofa ogg openal openexr openmp p2p pam pcre perforce perl php plugin png pnm postscript ppds pppd python qa qt3 quicktime quotas readline realmedia reflection reiser4 reiserfs rt2500pci rtc rtsp samba sasl scenarios sdl selinux session skins slang sox speex spell spl srteam sse sse2 ssl stream subtitles subversion svg swat tga theora tiff timidity tordns truetype tta unicode usb v4l vcd vidx vlm vorbis wavpack wifi wma wmf wmp wxwindows x86 xanim xfs xine xml xorg xprint xv xvid xvmc yahoo yv12 zlib zrtp zsh" ALSA_CARDS="ali5451 als4000 atiixp atiixp-modem bt87x ca0106 cmipci emu10k1 emu10k1x ens1370 ens1371 es1938 es1968 fm801 hda-intel intel8x0 intel8x0m maestro3 trident usb-audio via82xx via82xx-modem ymfpci" ALSA_PCM_PLUGINS="adpcm alaw asym copy dmix dshare dsnoop empty extplug file hooks iec958 ioplug ladspa lfloat linear meter mulaw multi null plug rate route share shm softvol" APACHE2_MODULES="access auth auth_dbm auth_anon auth_digest alias file-cache echo charset-lite cache disk-cache mem-cache ext-filter case_filter case-filter-in deflate mime-magic cern-meta expires headers usertrack unique-id proxy proxy-connect proxy-ftp proxy-http info include cgi cgid dav dav-fs vhost-alias speling rewrite log_config logio env setenvif mime status autoindex asis negotiation dir imap actions userdir so filter unique_id authz_host" ELIBC="glibc" INPUT_DEVICES="wacom evdev keyboard mouse" KERNEL="linux" LCD_DEVICES="bayrad cfontz cfontz633 glk hd44780 lb216 lcdm001 mtxorb ncurses text" LINGUAS="en en_GB en_US" USERLAND="GNU" VIDEO_CARDS="radeon"
Unset:  CPPFLAGS, CTARGET, EMERGE_DEFAULT_OPTS, INSTALL_MASK, LDFLAGS, PORTAGE_COMPRESS, PORTAGE_COMPRESS_FLAGS, PORTAGE_RSYNC_EXTRA_OPTS
Comment 1 GNUtoo 2008-04-12 22:22:16 UTC
ah i have forgetten...:
here's samba version:
net-fs/samba-3.0.28
Comment 2 Chris PeBenito (RETIRED) gentoo-dev 2008-04-15 11:45:40 UTC
are you trying to share a home directory?  If so make sure the samba_enable_home_dirs boolean is enabled.
Comment 3 GNUtoo 2008-04-15 20:32:06 UTC
(In reply to comment #2)
> are you trying to share a home directory?  If so make sure the
> samba_enable_home_dirs boolean is enabled.
> 
sorry it was that...
by the way thanks a lot