dwflo
14th April 2006, 05:46 AM
[root@xgl dwflo]# audit2allow -M local -l -i /var/log/messages
Generating type enforcment file: local.te
Compiling policy
checkmodule -M -m -o local.mod local.te
/usr/bin/audit2allow: (unknown source)::ERROR 'syntax error' at token '13' on line 4:
class dir { 13 13:46:05 13:47:41 13:48:28 13:50:45 Apr NetworkManager_disable_trans:0, allow_cvs_read_shadow:0, allow_execheap:0, allow_execmem:1, allow_execmod:1, allow_execstack:1, allow_ftpd_anon_write:0, allow_gssd_read_tmp:1, allow_httpd_anon_write
require {
checkmodule: error(s) encountered while parsing configuration
checkmodule: loading policy configuration from local.te
[root@xgl dwflo]# cat local.te
module local 1.0;
require {
class dir { 13 13:46:05 13:47:41 13:48:28 13:50:45 Apr NetworkManager_disable_trans:0, allow_cvs_read_shadow:0, allow_execheap:0, allow_execmem:1, allow_execmod:1, allow_execstack:1, allow_ftpd_anon_write:0, allow_gssd_read_tmp:1, allow_httpd_anon_write:0, allow_httpd_sys_script_anon_write:0, allow_java_execstack:0, allow_kerberos:1, allow_ptrace:0, allow_rsync_anon_write:0, allow_saslauthd_read_shadow:0, allow_smbd_anon_write:0, allow_ypbind:0, amanda_disable_trans:0, apmd_disable_trans:0, arpwatch_disable_trans:0, auditd_disable_trans:0, automount_disable_trans:0, automount_disable_trans:1, avahi_disable_trans:0, bluetooth_disable_trans:0, canna_disable_trans:0, cardmgr_disable_trans:0, clvmd_disable_trans:0, comsat_disable_trans:0, crond_disable_trans:0, cupsd_config_disable_trans:0, cupsd_disable_trans:0, cupsd_lpd_disable_trans:0, cvs_disable_trans:0, cyrus_disable_trans:0, dbskkd_disable_trans:0, dhcpc_disable_trans:0, dhcpd_disable_trans:0, dovecot_disable_trans:0, e_dirs:0, fcron_crond:0, fetchmail_disable_trans:0, fingerd_disable_trans:0, ftp_home_dir:0, ftpd_disable_trans:0, ftpd_is_daemon:1, getattr global_ssp:0, gpm_disable_trans:0, gssd_disable_trans:0, hald_disable_trans:0, hald_disable_trans:1, hotplug_disable_trans:0, hotplug_disable_trans:1, howl_disable_trans:0, hplip_disable_trans:0, httpd_builtin_scripting:1, httpd_can_network_connect:0, httpd_can_network_connect_db:0, httpd_can_network_relay:0, httpd_disable_trans:0, httpd_enable_cgi:1, httpd_enable_ftp_server:0, httpd_enable_homedirs:1, httpd_ssi_exec:1, httpd_suexec_disable_trans:0, httpd_tty_comm:0, httpd_unified:1, inetd_child_disable_trans:0, inetd_disable_trans:0, innd_disable_trans:0, irqbalance_disable_trans:0, isable_trans:0, kadmind_disable_trans:0, kernel: klogd_disable_trans:0, krb5kdc_disable_trans:0, ktalkd_disable_trans:0, lpd_disable_trans:0, mailman_mail_disable_trans:0, mysqld_disable_trans:0, named_disable_trans:0, named_write_master_zones:0, nfs_export_all_ro:1, nfs_export_all_rw:1, nfsd_disable_trans:0, nmbd_disable_trans:0, nscd_disable_trans:0, ntpd_disable_trans:0, pegasus_disable_trans:0, portmap_disable_trans:0, postfix_disable_trans:0, postgresql_disable_trans:0, pppd_can_insmod:0, pppd_disable_trans:0, pptp_disable_trans:0, privoxy_disable_trans:0, ptal_disable_trans:0, radiusd_disable_trans:0, radvd_disable_trans:0, rans:0, rdisc_disable_trans:0, read_default_t:1, readahead_disable_trans:0, restorecond_disable_trans:0, rlogind_disable_trans:0, rpcd_disable_trans:0, rshd_disable_trans:0, rsync_disable_trans:0, run_ssh_inetd:0, samba_enable_home_dirs:0, saslauthd_disable_trans:0, search secure_mode:0, secure_mode_insmod:0, secure_mode_policyload:0, sla smbd_disable_trans:0, snmpd_disable_trans:0, spamassasin_can_network:0, spamd_disable_trans:0, spamd_enable_home_dirs:1, squid_connect_any:0, squid_disab ssh_sysadm_login:0, stunnel_disable_trans:0, stunnel_is_daemon:0, swat_disable_trans:0, syslogd_disable_trans:0, system_crond_disable_trans:0, tcpd_disable_trans:0, telnetd_disable_trans:0, tftpd_disable_trans:0, udev_disable_trans:0, use_nfs_home_dirs:0, use_samba_ho user_ping:1, uucpd_disable_trans:0, winbind_disable_trans:0, write xdm_disable_trans:0, xend_disable_trans:0, xfs_disable_trans:0, xgl ypbind_disable_trans:0, yppasswdd_disable_trans:0, ypserv_disable_trans:0, ypxfr_disable_trans:0, zebra_disable_trans:0 };
class fd use;
class fifo_file getattr;
class file { getattr read write };
class process transition;
class sock_file getattr;
type etc_t;
type file_t;
type fsadm_t;
type hald_t;
type mount_t;
type ramfs_t;
type restorecon_t;
type rpm_script_t;
type setfiles_t;
type unconfined_t;
type xdm_t;
};
allow fsadm_t file_t:file read;
allow hald_t file_t:dir { 13 13:46:05 13:47:41 13:48:28 13:50:45 Apr NetworkManager_disable_trans:0, allow_cvs_read_shadow:0, allow_execheap:0, allow_execmem:1, allow_execmod:1, allow_execstack:1, allow_ftpd_anon_write:0, allow_gssd_read_tmp:1, allow_httpd_anon_write:0, allow_httpd_sys_script_anon_write:0, allow_java_execstack:0, allow_kerberos:1, allow_ptrace:0, allow_rsync_anon_write:0, allow_saslauthd_read_shadow:0, allow_smbd_anon_write:0, allow_ypbind:0, amanda_disable_trans:0, apmd_disable_trans:0, arpwatch_disable_trans:0, auditd_disable_trans:0, automount_disable_trans:0, automount_disable_trans:1, avahi_disable_trans:0, bluetooth_disable_trans:0, canna_disable_trans:0, cardmgr_disable_trans:0, clvmd_disable_trans:0, comsat_disable_trans:0, crond_disable_trans:0, cupsd_config_disable_trans:0, cupsd_disable_trans:0, cupsd_lpd_disable_trans:0, cvs_disable_trans:0, cyrus_disable_trans:0, dbskkd_disable_trans:0, dhcpc_disable_trans:0, dhcpd_disable_trans:0, dovecot_disable_trans:0, e_dirs:0, fcron_crond:0, fetchmail_disable_trans:0, fingerd_disable_trans:0, ftp_home_dir:0, ftpd_disable_trans:0, ftpd_is_daemon:1, getattr global_ssp:0, gpm_disable_trans:0, gssd_disable_trans:0, hald_disable_trans:0, hald_disable_trans:1, hotplug_disable_trans:0, hotplug_disable_trans:1, howl_disable_trans:0, hplip_disable_trans:0, httpd_builtin_scripting:1, httpd_can_network_connect:0, httpd_can_network_connect_db:0, httpd_can_network_relay:0, httpd_disable_trans:0, httpd_enable_cgi:1, httpd_enable_ftp_server:0, httpd_enable_homedirs:1, httpd_ssi_exec:1, httpd_suexec_disable_trans:0, httpd_tty_comm:0, httpd_unified:1, inetd_child_disable_trans:0, inetd_disable_trans:0, innd_disable_trans:0, irqbalance_disable_trans:0, isable_trans:0, kadmind_disable_trans:0, kernel: klogd_disable_trans:0, krb5kdc_disable_trans:0, ktalkd_disable_trans:0, lpd_disable_trans:0, mailman_mail_disable_trans:0, mysqld_disable_trans:0, named_disable_trans:0, named_write_master_zones:0, nfs_export_all_ro:1, nfs_export_all_rw:1, nfsd_disable_trans:0, nmbd_disable_trans:0, nscd_disable_trans:0, ntpd_disable_trans:0, pegasus_disable_trans:0, portmap_disable_trans:0, postfix_disable_trans:0, postgresql_disable_trans:0, pppd_can_insmod:0, pppd_disable_trans:0, pptp_disable_trans:0, privoxy_disable_trans:0, ptal_disable_trans:0, radiusd_disable_trans:0, radvd_disable_trans:0, rans:0, rdisc_disable_trans:0, read_default_t:1, readahead_disable_trans:0, restorecond_disable_trans:0, rlogind_disable_trans:0, rpcd_disable_trans:0, rshd_disable_trans:0, rsync_disable_trans:0, run_ssh_inetd:0, samba_enable_home_dirs:0, saslauthd_disable_trans:0, search secure_mode:0, secure_mode_insmod:0, secure_mode_policyload:0, sla smbd_disable_trans:0, snmpd_disable_trans:0, spamassasin_can_network:0, spamd_disable_trans:0, spamd_enable_home_dirs:1, squid_connect_any:0, squid_disab ssh_sysadm_login:0, stunnel_disable_trans:0, stunnel_is_daemon:0, swat_disable_trans:0, syslogd_disable_trans:0, system_crond_disable_trans:0, tcpd_disable_trans:0, telnetd_disable_trans:0, tftpd_disable_trans:0, udev_disable_trans:0, use_nfs_home_dirs:0, use_samba_ho user_ping:1, uucpd_disable_trans:0, winbind_disable_trans:0, xdm_disable_trans:0, xend_disable_trans:0, xfs_disable_trans:0, xgl ypbind_disable_trans:0, yppasswdd_disable_trans:0, ypserv_disable_trans:0, ypxfr_disable_trans:0, zebra_disable_trans:0 };
allow mount_t etc_t:file write;
allow restorecon_t xdm_t:fd use;
allow setfiles_t ramfs_t:fifo_file getattr;
allow setfiles_t ramfs_t:file getattr;
allow setfiles_t ramfs_t:sock_file getattr;
allow unconfined_t rpm_script_t:process transition;
allow unconfined_t self:dir write;
[root@xgl dwflo]#
[root@xgl dwflo]# semodule -i local.pp
bash: semodule: command not found
As you can see when I do the audit2allow, there is a syntax error, then cat the local.te.
semodule command not found!!!
vBulletin® v3.8.7, Copyright ©2000-2013, vBulletin Solutions, Inc.