FC12: 'sandbox -X' AVC's

Daniel J Walsh dwalsh at redhat.com
Thu Dec 17 19:46:27 UTC 2009


On 12/17/2009 11:49 AM, Christoph A. wrote:
> Hi,
> 
> after watching Dan's presentation (LPC) about sandbox
> in Fedora 12 I wanted to try it out, but I was not successfull.
> 
> I tried 'sandbox  -X xterm'
> and 'sandbox -X firefox' but both crashed immedeately, and I got AVC's.
> 
> package versions:
> 
> selinux-policy-targeted-3.6.32-56.fc12.noarch
> policycoreutils-2.0.74-17.fc12.i686
> policycoreutils-sandbox-2.0.74-17.fc12.i686
> selinux-policy-3.6.32-56.fc12.noarch
> policycoreutils-python-2.0.74-17.fc12.i686
> 
> avc's for 'sandbox -X firefox' attached.
> 
> Is this a known issue or should this work?
> 
> thanks!
> Christoph
> 
> 
> 
> 
> --
> fedora-selinux-list mailing list
> fedora-selinux-list at redhat.com
> https://www.redhat.com/mailman/listinfo/fedora-selinux-list
sandbox -t sandbox_web_t firefox 

Should work for firefox.

Not sure what is going wrong with sandbox -X xterm.

Did you reboot after installing policycoreutils-sandbox?

You need to reboot in order to setup the namespace stuff.




More information about the fedora-selinux-list mailing list