Gentoo Websites Logo
Go to: Gentoo Home Documentation Forums Lists Bugs Planet Store Wiki Get Gentoo!
Bug 456910 - portage_t and openrc_cgroup_release_t don't have access to /run/nscd/socket
Summary: portage_t and openrc_cgroup_release_t don't have access to /run/nscd/socket
Status: VERIFIED FIXED
Alias: None
Product: Gentoo Linux
Classification: Unclassified
Component: SELinux (show other bugs)
Hardware: All Linux
: Normal normal (vote)
Assignee: Sven Vermeulen (RETIRED)
URL:
Whiteboard: sec-policy r12
Keywords:
Depends on:
Blocks:
 
Reported: 2013-02-12 10:47 UTC by Mira Ressel
Modified: 2013-03-29 10:55 UTC (History)
1 user (show)

See Also:
Package list:
Runtime testing required: ---


Attachments

Note You need to log in before you can comment on or make changes to this bug.
Description Mira Ressel 2013-02-12 10:47:03 UTC
Processes running as portage_t or openrc_cgroup_release_t don't have access to /run/nscd/socket. This doesn't look like a security gain, so they should be granted either nscd_socket_use() or auth_use_nsswitch().
Comment 1 Sven Vermeulen (RETIRED) gentoo-dev 2013-02-12 19:15:49 UTC
Fixed in repository and will be in rev 12.
Also, openrc now depends on selinux-openrc if USE="selinux"
Comment 2 Sven Vermeulen (RETIRED) gentoo-dev 2013-03-09 12:41:26 UTC
rev 12 in main tree, ~arch'ed
Comment 3 Sven Vermeulen (RETIRED) gentoo-dev 2013-03-29 10:55:10 UTC
stabilized