Research Menu

.
Skip Search Box

SELinux Mailing List

Re: X avcs

From: Xavier Toth <txtoth_at_gmail.com>
Date: Fri, 28 Dec 2007 10:54:45 -0600


What about labeling notification-daemon as other gnome apps have been labeled (user_xpriv_t)?

On Dec 26, 2007 3:01 PM, Xavier Toth <txtoth@gmail.com> wrote:
> swo_u who is running ranged (systemlow-systemhigh) uses newrole to
> launch an X windows app at systemhigh and then I get avcs like the
> following:
>
> avc: denied { receive } for request=X11:ChangeWindowAttributes
> comm=/usr/libexec/notification-daemon resid=3800036 restype=WINDOW
> scontext=swo_u:user_r:user_t:s0-s15:c0.c1023
> tcontext=swo_u:object_r:user_t:s15:c0.c1023 tclass=x_drawable
> avc: denied { get_property } for request=X11:GetProperty
> comm=/usr/libexec/notification-daemon resid=3800036 restype=WINDOW
> scontext=swo_u:user_r:user_t:s0-s15:c0.c1023
> tcontext=swo_u:object_r:user_t:s15:c0.c1023 tclass=x_drawable
> avc: denied { receive } for comm=/usr/libexec/notification-daemon
> event=X11:MapNotify scontext=swo_u:user_r:user_t:s0-s15:c0.c1023
> tcontext=swo_u:object_r:user_manage_xevent_t:s15:c0.c1023
> tclass=x_event
> avc: denied { receive } for comm=/usr/libexec/notification-daemon
> event=X11:VisibilityNotify
> scontext=swo_u:user_r:user_t:s0-s15:c0.c1023
> tcontext=swo_u:object_r:user_default_xevent_t:s15:c0.c1023
> tclass=x_event
> avc: denied { receive } for comm=/usr/libexec/notification-daemon
> event=X11:PropertyNotify scontext=swo_u:user_r:user_t:s0-s15:c0.c1023
> tcontext=swo_u:object_r:user_property_xevent_t:s15:c0.c1023
> tclass=x_event
> avc: denied { receive } for comm=/usr/libexec/notification-daemon
> event=X11:FocusIn scontext=swo_u:user_r:user_t:s0-s15:c0.c1023
> tcontext=swo_u:object_r:user_focus_xevent_t:s15:c0.c1023
> tclass=x_event
> avc: denied { getattr } for request=X11:GetGeometry
> comm=/usr/libexec/notification-daemon resid=3800036 restype=WINDOW
> scontext=swo_u:user_r:user_t:s0-s15:c0.c1023
> tcontext=swo_u:object_r:user_t:s15:c0.c1023 tclass=x_drawable
> avc: denied { read } for request=X11:GetProperty
> comm=/usr/libexec/notification-daemon property=WM_NAME
> scontext=swo_u:user_r:user_t:s0-s15:c0.c1023
> tcontext=swo_u:object_r:user_default_xproperty_t:s15:c0.c1023
> tclass=x_property
>
> I'm not familiar with /usr/libexec/notification-daemon and what it
> does and I'm thinking that it's probably not the best idea to use
> mls_xwin_read_all_levels for user_t.. Any suggestions?
>

--
This message was distributed to subscribers of the selinux mailing list.
If you no longer wish to subscribe, send mail to majordomo@tycho.nsa.gov with
the words "unsubscribe selinux" without quotes as the message.
Received on Fri 28 Dec 2007 - 11:54:54 EST
 

Date Posted: Jan 15, 2009 | Last Modified: Jan 15, 2009 | Last Reviewed: Jan 15, 2009

 
bottom

National Security Agency / Central Security Service