Gentoo Websites Logo
Go to: Gentoo Home Documentation Forums Lists Bugs Planet Store Wiki Get Gentoo!
Bug 461576 - selinux-irc (-9999) policy blocks irssi from reading ca-certificates when using ssl connection
Summary: selinux-irc (-9999) policy blocks irssi from reading ca-certificates when usi...
Status: VERIFIED FIXED
Alias: None
Product: Gentoo Linux
Classification: Unclassified
Component: SELinux (show other bugs)
Hardware: All Linux
: Normal normal (vote)
Assignee: Sven Vermeulen (RETIRED)
URL:
Whiteboard: sec-policy r1
Keywords:
Depends on:
Blocks:
 
Reported: 2013-03-12 19:46 UTC by Amadeusz Sławiński
Modified: 2013-06-16 17:57 UTC (History)
1 user (show)

See Also:
Package list:
Runtime testing required: ---


Attachments

Note You need to log in before you can comment on or make changes to this bug.
Description Amadeusz Sławiński 2013-03-12 19:46:21 UTC
Enforcing:

Mar 12 20:39:50 lain kernel: [ 1687.335751] type=1400 audit(1363117190.389:122): avc:  denied  { search } for  pid=4390 comm="irssi" name="ca-certificates" dev="dm-0" ino=12191671 scontext=staff_u:staff_r:irc_t tcontext=system_u:object_r:cert_t tclass=dir

Permissive:

Mar 12 20:29:35 lain kernel: [ 1073.410874] type=1400 audit(1363116575.245:97): avc:  denied  { search } for  pid=2801 comm="irssi" name="ca-certificates" dev="dm-0" ino=12191671 scontext=staff_u:staff_r:irc_t tcontext=system_u:object_r:cert_t tclass=dir
Mar 12 20:29:35 lain kernel: [ 1073.434008] type=1400 audit(1363116575.268:98): avc:  denied  { getattr } for  pid=2801 comm="irssi" path="/usr/share/ca-certificates/mozilla/UTN_USERFirst_Hardware_Root_CA.crt" dev="dm-0" ino=6558932 scontext=staff_u:staff_r:irc_t tcontext=system_u:object_r:cert_t tclass=file
Mar 12 20:29:35 lain kernel: [ 1073.434048] type=1400 audit(1363116575.268:99): avc:  denied  { read } for  pid=2801 comm="irssi" name="UTN_USERFirst_Hardware_Root_CA.crt" dev="dm-0" ino=6558932 scontext=staff_u:staff_r:irc_t tcontext=system_u:object_r:cert_t tclass=file
Mar 12 20:29:35 lain kernel: [ 1073.434063] type=1400 audit(1363116575.268:100): avc:  denied  { open } for  pid=2801 comm="irssi" path="/usr/share/ca-certificates/mozilla/UTN_USERFirst_Hardware_Root_CA.crt" dev="dm-0" ino=6558932 scontext=staff_u:staff_r:irc_t tcontext=system_u:object_r:cert_t tclass=file



Reproducible: Always
Comment 1 Sven Vermeulen (RETIRED) gentoo-dev 2013-03-17 10:09:34 UTC
In repo, will be in r13
Comment 2 Sven Vermeulen (RETIRED) gentoo-dev 2013-03-17 10:10:34 UTC
repo commit c0130ed
Comment 3 Sven Vermeulen (RETIRED) gentoo-dev 2013-05-06 18:25:03 UTC
In main tree,  ~arch'ed (20130424-r1 release)
Comment 4 Sven Vermeulen (RETIRED) gentoo-dev 2013-06-16 17:57:02 UTC
Now stable in repo