Fedora Linux Support Community & Resources Center

Go Back   FedoraForum.org > The Dungeon > Archived (Click Header To See Sub-Forums) > Alpha, Beta & Snapshots Discussions (Fedora 10 Only)
FedoraForum Search

Forgot Password? Join Us!

Alpha, Beta & Snapshots Discussions (Fedora 10 Only) Post Development Version comments and questions that don't belong in Bugzilla here. These posts will be moved or deleted once the Final version is released

 
 
Thread Tools Search this Thread Display Modes
  #1  
Old 14th October 2008, 08:42 PM
cgrim's Avatar
cgrim Offline
Registered User
 
Join Date: Jun 2007
Location: Czech republic
Posts: 178
Question unconfined_execmem_exec_t

After upgrade on Fedora 10 a lot of applications (vlc, mplayer, amarok, kino, avidemux, ...) doesn't work because of SELinux prevention. I have to run something like this for all that aplications:
Code:
chcon -t unconfined_execmem_exec_t '/usr/bin/gmplayer'
SETroubleShooter shows this:
SELinux is preventing gmplayer from changing a writable memory segment executable.
The gmplayer application attempted to change the access protection of memory (e.g., allocated using malloc). This is a potential security problem. Applications should not be doing this. Applications are sometimes coded incorrectly and request this permission. The SELinux Memory Protection Tests web page explains how to remove this requirement. If gmplayer does not work and you need it to work, you can configure SELinux temporarily to allow this access until the application is fixed. Please file a bug report against this package.


Is it really application bug or is it SELinux problem or have I some virus which attacked that applications? ;-)
__________________
Now 5 running Fedora instances at home ...
  #2  
Old 15th October 2008, 06:04 AM
SlowJet Offline
Registered User
 
Join Date: Jan 2005
Posts: 5,002
I'm assuming those are new KDE-4 apps and the "what the heck are they doing now?" has been detected by the selinux man.

I would do these things,

1. yum update to the newest selinux-policy.
2. touch /.autorelabel
reboot

If the gmplayer still doesn't work,
file a bugZ then
3. SELinux Management - in Gnome it is under System, Administration
Select boolean, schroll down to global
Click on check box - Allow_execmem (way over on the right after the vey long .....allow_excmem

Besure to check selinux updates to see if it works because now any incorrect program can mix data in code pages.

Also see
man setools - schroll to bottom
man getsebool
man setsebool
for cli usage.

SJ
__________________
Do the Math
  #3  
Old 15th October 2008, 07:57 AM
cgrim's Avatar
cgrim Offline
Registered User
 
Join Date: Jun 2007
Location: Czech republic
Posts: 178
I have everything updated on the newest version.
Yesterday I tried autorelabel, but after filling whole display by asterixes it freezes ... I waited for about one hour and nothing changed. So I restarted system. Now it's still the same

Another applications which have problems with SELinux are: blender, compiz, opera, googleEarth, k3b, glxinfo, quake3, ...

No w I enabled allow_execmem, allow_execstack and allow_execmod for global and everything started to work. -> Thank you

So I will generate a lot of bugzilla records for all that applications listed above as SELinux TroubleShooter said to me ;-)
__________________
Now 5 running Fedora instances at home ...
  #4  
Old 15th October 2008, 08:29 AM
SlowJet Offline
Registered User
 
Join Date: Jan 2005
Posts: 5,002
Yeah, BZ the programs, they may not be coded clean yet.

SJ
__________________
Do the Math
  #5  
Old 15th October 2008, 01:10 PM
cgrim's Avatar
cgrim Offline
Registered User
 
Join Date: Jun 2007
Location: Czech republic
Posts: 178
amarok
compiz
blender

... tomorrow I will continue with other programs ;-)
__________________
Now 5 running Fedora instances at home ...
  #6  
Old 16th October 2008, 09:20 AM
cgrim's Avatar
cgrim Offline
Registered User
 
Join Date: Jun 2007
Location: Czech republic
Posts: 178
The result is: nVidia drivers are causing this problem in the most cases. I tried to contact nVidia. Does anyone has any experiance with them? How they react on linux drivers request?

Only in k3b is another situation https://bugzilla.rpmfusion.org/show_bug.cgi?id=69
__________________
Now 5 running Fedora instances at home ...
  #7  
Old 16th October 2008, 10:54 AM
brebs's Avatar
brebs Offline
Banned
 
Join Date: Apr 2008
Posts: 558
Quote:
Originally Posted by cgrim View Post
I tried to contact nVidia.
Should create a thread in the nvidia forum.
 

Tags
unconfinedexecmemexect

Thread Tools Search this Thread
Search this Thread:

Advanced Search
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off

Forum Jump


Current GMT-time: 23:56 (Sunday, 19-05-2013)

TopSubscribe to XML RSS for all Threads in all ForumsFedoraForumDotOrg Archive
logo

All trademarks, and forum posts in this site are property of their respective owner(s).
FedoraForum.org is privately owned and is not directly sponsored by the Fedora Project or Red Hat, Inc.

Privacy Policy | Term of Use | Posting Guidelines | Archive | Contact Us | Founding Members

Powered by vBulletin® Copyright ©2000 - 2012, vBulletin Solutions, Inc.

FedoraForum is Powered by RedHat