Re: motion

Lukas Vrabec <[email protected]>
Newsgroups gmane.linux.redhat.fedora.selinux
Organization Red Hat, Inc.
Message-ID <[email protected]>
On 04/18/2018 05:33 PM, [email protected] wrote:
> On Sun, 15 Apr 2018 20:48. ukas Vrabec <[email protected]> wrote:
>> On 04/12/2018 10:49 PM, [email protected] wrote:
>>> Got a CentOS 7 box running motion. Selinux is complaining that one of the
>>> scripts motion runs is mislabeled. Here's what it is.
>>> system_u:object_r:nfs_t:s0       /home/motion/bin/on_move_end
>>>
>>> Now, ~motion is NFS mounted, and we've got use_nfs_home_dirs --> on, so
>>> what *would* the proper label be, or do I really need to create a policy
>>> for this?
>>
>> Could you please reproduce issue on your system and then attach output of:
>>
>> # ausearch -m AVC -ts today
>>
> It's been a busy week - sorry it took this long to respond. Do you
> *really* want all of it - this happens whenever someone goes into the
> secure room and is on video... and there are four cameras. Just today, I
> get 79k worth of o/p.
> 
> Here's the most recent minute's o/p:
> 
> time->Wed Apr 18 11:21:32 2018
> type=PROCTITLE msg=audit(1524064892.294:35325):
> proctitle=7368002D63002F686F6D652F6D6F74696F6E2F62696E2F6F6E5F6D6F76655F656E64202F686F6D652F6D6F74696F6E2F63616D6572612F323031382D30342D31382F323031382D30342D31382D3131313134352D31322D6172676F2D312E617669203120323031382D30342D3138002026
> type=SYSCALL msg=audit(1524064892.294:35325): arch=c000003e syscall=59
> success=yes exit=0 a0=af4fe0 a1=af5040 a2=af3b90 a3=7ffd1c86d700 items=0
> ppid=1438 pid=11961 auid=4294967295 uid=489 gid=39 euid=489 suid=489
> fsuid=489 egid=39 sgid=39 fsgid=39 tty=(none) ses=4294967295
> comm="on_move_end" exe="/usr/bin/bash" subj=system_u:system_r:motion_t:s0
> key=(null)
> type=AVC msg=audit(1524064892.294:35325): avc:  denied  { execute_no_trans
> } for  pid=11961 comm="sh" path="/home/motion/bin/on_move_end" dev="0:46"
> ino=53198849 scontext=system_u:system_r:motion_t:s0
> tcontext=system_u:object_r:nfs_t:s0 tclass=file
> type=AVC msg=audit(1524064892.294:35325): avc:  denied  { execute } for 
> pid=11961 comm="sh" name="on_move_end" dev="0:46" ino=53198849
> scontext=system_u:system_r:motion_t:s0 tcontext=system_u:object_r:nfs_t:s0
> tclass=file
> ----
> time->Wed Apr 18 11:21:32 2018
> type=PROCTITLE msg=audit(1524064892.291:35324):
> proctitle=7368002D63002F686F6D652F6D6F74696F6E2F62696E2F6F6E5F6D6F76655F656E64202F686F6D652F6D6F74696F6E2F63616D6572612F323031382D30342D31382F323031382D30342D31382D3131313134352D31322D6172676F2D312E617669203120323031382D30342D3138002026
> type=SYSCALL msg=audit(1524064892.291:35324): arch=c000003e syscall=59
> success=yes exit=0 a0=432503 a1=7ff42f7f9b00 a2=7ffc2ba4b760
> a3=7ff42f7fb730 items=0 ppid=1438 pid=11961 auid=4294967295 uid=489 gid=39
> euid=489 suid=489 fsuid=489 egid=39 sgid=39 fsgid=39 tty=(none)
> ses=4294967295 comm="sh" exe="/usr/bin/bash"
> subj=system_u:system_r:motion_t:s0 key=(null)
> type=AVC msg=audit(1524064892.291:35324): avc:  denied  { execute_no_trans
> } for  pid=11961 comm="motion" path="/usr/bin/bash" dev="dm-1" ino=98
> scontext=system_u:system_r:motion_t:s0
> tcontext=system_u:object_r:shell_exec_t:s0 tclass=file
> ----
> time->Wed Apr 18 11:22:22 2018
> type=PROCTITLE msg=audit(1524064942.249:35327):
> proctitle=2F62696E2F7368002F686F6D652F6D6F74696F6E2F62696E2F6F6E5F6D6F76655F656E64002F686F6D652F6D6F74696F6E2F63616D6572612F323031382D30342D31382F323031382D30342D31382D3131323033342D30362D6172676F2D332E617669003300323031382D30342D3138
> type=SYSCALL msg=audit(1524064942.249:35327): arch=c000003e syscall=59
> success=yes exit=0 a0=78eb50 a1=78eb70 a2=78e8b0 a3=7ffdcf4d8af0 items=0
> ppid=12042 pid=12043 auid=4294967295 uid=489 gid=39 euid=489 suid=489
> fsuid=489 egid=39 sgid=39 fsgid=39 tty=(none) ses=4294967295 comm="uname"
> exe="/usr/bin/uname" subj=system_u:system_r:motion_t:s0 key=(null)
> type=AVC msg=audit(1524064942.249:35327): avc:  denied  { execute_no_trans
> } for  pid=12043 comm="on_move_end" path="/usr/bin/uname" dev="dm-1"
> ino=259829 scontext=system_u:system_r:motion_t:s0
> tcontext=system_u:object_r:bin_t:s0 tclass=file
> ----
> time->Wed Apr 18 11:22:22 2018
> type=PROCTITLE msg=audit(1524064942.249:35326):
> proctitle=2F62696E2F7368002F686F6D652F6D6F74696F6E2F62696E2F6F6E5F6D6F76655F656E64002F686F6D652F6D6F74696F6E2F63616D6572612F323031382D30342D31382F323031382D30342D31382D3131323033342D30362D6172676F2D332E617669003300323031382D30342D3138
> type=SYSCALL msg=audit(1524064942.249:35326): arch=c000003e syscall=21
> success=yes exit=0 a0=78eb50 a1=1 a2=7ffdcf4d8d40 a3=7ffdcf4d89d0 items=0
> ppid=12042 pid=12043 auid=4294967295 uid=489 gid=39 euid=489 suid=489
> fsuid=489 egid=39 sgid=39 fsgid=39 tty=(none) ses=4294967295
> comm="on_move_end" exe="/usr/bin/bash" subj=system_u:system_r:motion_t:s0
> key=(null)
> type=AVC msg=audit(1524064942.249:35326): avc:  denied  { execute } for 
> pid=12043 comm="on_move_end" name="uname" dev="dm-1" ino=259829
> scontext=system_u:system_r:motion_t:s0 tcontext=system_u:object_r:bin_t:s0
> tclass=file
> 
>    mark
> 


We should create boolean which allow motion to access nfs files. Could
you create bugzilla for this ?

Thanks,
Lukas.

-- 
Lukas Vrabec
Software Engineer, Security Technologies
Red Hat, Inc.
_______________________________________________
selinux mailing list -- [email protected]
To unsubscribe send an email to [email protected]
Fedora Code of Conduct: https://getfedora.org/code-of-conduct.html
List Guidelines: https://fedoraproject.org/wiki/Mailing_list_guidelines
List Archives: https://lists.fedoraproject.org/archives/list/[email protected]/message/RSVGQYQKNUQGJ6UY6RF27X3DBL4UIGJ5/
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.