Package: selinux-policy-default
Version: 2:0.0.20080702-6
Severity: grave

I have a machine where the unconfined policy is loaded but not used, so
my only way in is staff_u with staff_r and transition to sysadm_r:

| # id   
| uid=0(root) gid=0(root) groups=0(root) 
context=staff_u:sysadm_r:sysadm_t:s0-s0:c0.c1023

Now dpkg fails to execute initrc_exec_t with the following audit
message:

| audit(1241011095.115:260): security_compute_sid:  invalid context 
staff_u:sysadm_r:initrc_t:s0 for 
scontext=staff_u:sysadm_r:dpkg_t:s0-s0:c0.c1023 
tcontext=system_u:object_r:initrc_exec_t:s0 tclass=process

This makes it impossible to install/remove any package which wants to
use invoke-rc.d.

Bastian

-- 
Deflector shields just came on, Captain.



-- 
To UNSUBSCRIBE, email to [email protected]
with a subject of "unsubscribe". Trouble? Contact [email protected]

Reply via email to