SELinux deny gdm-binary to access /boot

Mitsuho Iizuka m-iizuka at cp.jp.nec.com
Fri Nov 16 02:01:12 UTC 2007


Hi,

From: Daniel J Walsh <dwalsh at redhat.com>
Subject: Re: SELinux deny gdm-binary to access /boot
Date: Thu, 15 Nov 2007 11:37:33 -0500

> If you chcon -t bin_t /usr/sbin/gdm
> 
> Does the problem disappear?

I will study security context and try this. Thank you. It seems to me
FAQ as I remember like this article before. I'm sorry.

But viewing gdm source and output of 'strings gdm-binary' and 'grep
/boot /etc/*' indicated me to decide it was different case.

> /usr/sbin/gdm is a shell script and it is executing
> 
> test -f /etc/profile && . /etc/profile

Do you mean 'test -f /etc/profile && ./etc/profile' accessing some
files in /boot partiotion ? 
 
Thnaks.

Regards,
// Mitsuho Iizuka




More information about the fedora-list mailing list