Summary: | net-analyzer/vnstatd has an incorrect label for /etc/init.d/vnstatd | ||
---|---|---|---|
Product: | Gentoo Linux | Reporter: | Eric Gisse <jowr.pi> |
Component: | SELinux | Assignee: | Sven Vermeulen (RETIRED) <swift> |
Status: | RESOLVED FIXED | ||
Severity: | normal | CC: | selinux |
Priority: | Normal | ||
Version: | unspecified | ||
Hardware: | All | ||
OS: | Linux | ||
Whiteboard: | sec-policy r1 | ||
Package list: | Runtime testing required: | --- |
Description
Eric Gisse
2014-11-08 00:46:59 UTC
Hi Eric, good catch. I've fixed this in our repository (which means that the live ebuilds already have the fix in them). The fix will be part of the next policy release ebuilds as well (r8 and higher) Looking at this again I realized I wasn't fully specific about vnstatd The init script is mislabled, but it also applies to labeling /usr/bin/vnstatd which normally has no specific: # ls -Z /usr/bin/vnstatd root:object_r:bin_t /usr/bin/vnstatd Incremental work. You think you fixed something, and you come back a day later and see a periodic complaint in the avc log and think "hmmm..." Ok, context change for /usr/bin/vnstatd added as well. r1 is now stable |