public inbox for gentoo-hardened@lists.gentoo.org
 help / color / mirror / Atom feed
* [gentoo-hardened] mysql 4.1 requires shlib_t:file execmod?
@ 2005-10-22 14:15 Antoine Martin
  2005-10-22 14:39 ` Dave Strydom
  2005-10-22 14:53 ` pageexec
  0 siblings, 2 replies; 34+ messages in thread
From: Antoine Martin @ 2005-10-22 14:15 UTC (permalink / raw
  To: SELinux, gentoo-hardened

Hi,

I've upgraded a (gentoo x86 selinux) system from MySQL 4.0 to 4.1, and
since then some of the software that uses mysql-libs refuse to run
without 'shlib_t:file execmod'.

ie: when starting postfix (built and rebuilt with mysql support):
postfix: error while loading shared
libraries: /usr/lib/libmysqlclient.so.14: cannot restore segment prot
after reloc: Permission denied

And here is the audit message:
[ 3159.289877] audit(1130082418.254:1085): avc:  denied  { execmod } for
pid=7905 comm="postfix" name="libmysqlclient.so.14.0.0" dev=md3
ino=84506 scontext=root:sysadm_r:postfix_postdrop_t
tcontext=system_u:object_r:shlib_t tclass=file

But other software does not needed it (mysql client, pdns, etc) even
though they are linked to the same library file...
What gives?

Thanks
Antoine

-- 
gentoo-hardened@gentoo.org mailing list



^ permalink raw reply	[flat|nested] 34+ messages in thread

end of thread, other threads:[~2005-11-15  1:34 UTC | newest]

Thread overview: 34+ messages (download: mbox.gz follow: Atom feed
-- links below jump to the message on this page --
2005-10-22 14:15 [gentoo-hardened] mysql 4.1 requires shlib_t:file execmod? Antoine Martin
2005-10-22 14:39 ` Dave Strydom
2005-10-22 16:33   ` Antoine Martin
2005-10-22 16:38     ` Antoine Martin
2005-10-22 14:53 ` pageexec
2005-10-22 15:45   ` Antoine Martin
2005-10-22 15:53     ` pageexec
2005-10-22 16:37       ` Antoine Martin
2005-10-22 17:24         ` pageexec
2005-10-22 17:31           ` Antoine Martin
2005-10-22 17:56             ` Petre Rodan
2005-10-23 20:42               ` Antoine Martin
2005-10-24 13:47                 ` pageexec
2005-10-24 19:15                   ` Antoine Martin
2005-10-24 21:23                     ` pageexec
2005-10-24 21:29                       ` Antoine Martin
2005-10-24 23:05                         ` pageexec
2005-10-25 10:45                           ` Antoine Martin
2005-10-25 12:04                             ` pageexec
2005-10-25 18:52                           ` solar
2005-10-25 20:55                             ` [gentoo-hardened] " Antoine Martin
2005-10-22 17:31         ` [gentoo-hardened] " solar
2005-10-22 17:41           ` Antoine Martin
2005-10-22 18:10             ` solar
2005-10-23 17:54               ` [gentoo-hardened] SELinux n00b questions Dale Pontius
2005-10-26 22:59                 ` Chris PeBenito
2005-10-27  1:33                   ` Dale Pontius
2005-10-31  3:19                     ` Chris PeBenito
2005-11-14  1:51                       ` Dale Pontius
2005-11-14  8:20                         ` Peter Shaw
2005-11-14 22:37                           ` Dale Pontius
2005-11-14 22:53                             ` Antoine Martin
2005-11-15  1:23                             ` Dale Pontius
2005-10-23 19:06               ` [gentoo-hardened] mysql 4.1 requires shlib_t:file execmod? Antoine Martin

This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox