Fedora Linux Support Community & Resources Center

Go Back   FedoraForum.org > Fedora 17/18 > Security and Privacy
FedoraForum Search

Forgot Password? Join Us!

Security and Privacy Sadly, malware, spyware, hackers and privacy threats abound in today's world. Let's be paranoid and secure our penguins, and slam the doors on privacy exploits.

Reply
 
Thread Tools Search this Thread Display Modes
  #1  
Old 15th July 2011, 09:52 PM
KBerger Offline
Registered User
 
Join Date: Jul 2011
Posts: 8
linuxfirefox
SELinux is preventing /usr/libexec/abrt-hook-ccpp from using the sys_ptrace capabilit

This is the "alert" I've received from SElinux Alert Browser after closing "rythmbox" application that opened my CreativeZen mediaplayer:
Code:
SELinux is preventing /usr/libexec/abrt-hook-ccpp from using the sys_ptrace capability
in dmesg it has:
Code:
rhythmbox[2727]: segfault at 3473580 ip 0000000003473580 sp 00007fffd8523d58 error 15
Then it gives me a funny suggestions:
Code:
If you believe that abrt-hook-ccpp should have the sys_ptrace capability by default.
Then you should report this as a bug.
I actually have no idea whether or not I really NEED this "abrt-hook-ccpp" thing on my computer, but it was installed by default in my Fedora 15 installation. So my first and last guess is, those guys who included it into the default installation (hope they visit this forum from time to time ) should also know better, whether or not
Code:
 abrt-hook-ccpp should have the sys_ptrace capability by default
My humble understanding of what's going on suggests that it was the rhythmbox crash which provoked some action by abrt-hook-ccpp. Perhaps the thing wanted to ptrace the system calls in order to create a bug report. In that case I don't see why it should NOT have "the sys_ptrace capability by default". Or othewise why do I need this another piece of software on my computer when it is not allowed to do its job???
...While I'm deeply impressed with how SELinux stands on guard of my security and all that, there is a funny feeling that SELinux should be installed along with some default policies that would allow reasonable "freedom" for average computer usage. Or when installing abrt-hook-ccpp it should add a corresponding exception to these policies.

With all due respect,
Kostya
Reply With Quote
  #2  
Old 18th July 2011, 10:52 PM
kayvan Offline
Registered User
 
Join Date: Jun 2005
Posts: 11
linuxfirefox
Re: SELinux is preventing /usr/libexec/abrt-hook-ccpp from using the sys_ptrace capab

I am getting the same issue here. Latest Fedora 15, updated.

"You should report this as a bug.
You can generate a local policy module to allow this access.
Allow this access for now by executing:
# grep abrt-hook-ccpp /var/log/audit/audit.log | audit2allow -M mypol
# semodule -i mypol.pp"

What is the correct solution?

Thanks.
Reply With Quote
  #3  
Old 18th July 2011, 11:07 PM
David Batson Offline
Registered User
 
Join Date: Jul 2009
Posts: 1,158
linuxopera
Re: SELinux is preventing /usr/libexec/abrt-hook-ccpp from using the sys_ptrace capab

Quote:
Originally Posted by kayvan View Post
I am getting the same issue here. Latest Fedora 15, updated.

"You should report this as a bug.
You can generate a local policy module to allow this access.
Allow this access for now by executing:
# grep abrt-hook-ccpp /var/log/audit/audit.log | audit2allow -M mypol
# semodule -i mypol.pp"

What is the correct solution?

Thanks.
1) Report as a bug at Fedora Bugzilla: https://bugzilla.redhat.com/enter_bu...product=Fedora

2) Start Terminal and log in as root. I always type su - {that's su[SPACE][HYPHEN] press ENTER} then type root's password {press ENTER}. You will see root's prompt #.
3) Type in grep abrt-hook-ccpp /var/log/audit/audit.log | audit2allow -M mypol {ENTER}.
4) Type in semodule -i mypol.pp" {ENTER}.
5) May have to logout/login or even reboot for changes to take effect - not sure.

6) Likely a future update of SELinux or another rpm will fix this (more likely if a bug report is filed).
__________________
Fedora 18 Gnome on a ThinkPad X220, i5-2540M CPU, Intel HD Graphics 3000, Intel N 6205 wireless, and Sierra Wireless 754S Mobile Hotspot (AT&T)

Last edited by David Batson; 18th July 2011 at 11:09 PM.
Reply With Quote
  #4  
Old 12th August 2011, 03:38 AM
Redagadir Offline
Registered User
 
Join Date: Aug 2011
Posts: 95
windows_xp_2003firefox
Re: SELinux is preventing /usr/libexec/abrt-hook-ccpp from using the sys_ptrace capab

maybe you should disable the abrt facility...
Reply With Quote
Reply

Tags
capabilit, preventing, selinux, sysptrace

Thread Tools Search this Thread
Search this Thread:

Advanced Search
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off

Forum Jump

Similar Threads
Thread Thread Starter Forum Replies Last Post
SELinux is preventing Blisk Using Fedora 19 7th June 2011 06:25 AM
SELinux is preventing NetworkManager jhnhgs75 Using Fedora 0 8th December 2009 10:17 AM
SElinux is preventing... Beralus Security and Privacy 4 18th November 2008 08:24 AM
SELinux is preventing... T3256 Security and Privacy 16 19th October 2008 04:50 AM
selinux preventing lircmd kwhiskers Security and Privacy 2 17th November 2007 07:47 AM


Current GMT-time: 01:51 (Thursday, 20-06-2013)

TopSubscribe to XML RSS for all Threads in all ForumsFedoraForumDotOrg Archive
logo

All trademarks, and forum posts in this site are property of their respective owner(s).
FedoraForum.org is privately owned and is not directly sponsored by the Fedora Project or Red Hat, Inc.

Privacy Policy | Term of Use | Posting Guidelines | Archive | Contact Us | Founding Members

Powered by vBulletin® Copyright ©2000 - 2012, vBulletin Solutions, Inc.

FedoraForum is Powered by RedHat